CVE-2026-5077Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the malicious post to be published and displayed with a featured image in the Home Page blog section.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 305-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5077 Stored Cross-Site Scripting in Total WordPress Theme Versions Up To 2.2.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5077

    Post summary

    CVE-2026-5077 is presented as a stored XSS flaw affecting Total WordPress Theme versions up to 2.2.1, with no PoC, exploit, or patch details mentioned.

    0001066
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5077 The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping w… https://www.cve.org/CVERecord?id=CVE-2026-5077 ----- Traducción: CVE-2026-5077 El … http://infoflow.cloud`

    Post summary

    A CVE for the Total WordPress theme is highlighted, noting a stored XSS flaw in post titles; no PoC, exploit code, active exploitation, or patch details are provided.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5077 The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping w… https://www.cve.org/CVERecord?id=CVE-2026-5077

    Post summary

    This statement announces CVE‑2026‑5077, a stored XSS flaw in the WordPress Total theme (up to 2.2.1) that allows attackers to inject malicious code via post titles, with no mention of exploits, mitigation, or mitigation possession.

    00000230
    57.4K followersView on X

Explore more