CVE-2026-39548: WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
Metrics
- CVSS v3.1
- 7.1
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Reflected cross-site scripting (XSS) vulnerability affects the MagOne WordPress theme by Sneeit in versions 9.0 and earlier. An unauthenticated attacker can deliver a malicious link to a victim over the network, and when the victim clicks it, the attacker's script executes inside the victim's browser session on the affected site. Successful exploitation lets an attacker read browser-accessible data such as session cookies, inject content into the page, and trigger minor disruption of the user's experience. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment an upstream fix is published.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds including Patchstack within minutes of publication and matched against customer images, including custom-built images that bundle the MagOne theme. Any image carrying MagOne 9.0 or earlier is flagged automatically.
AvailableHarborGuard scores this finding at CVSS 7.1 (High) and weights it against each environment's compliance policy to determine urgency and ownership. Triage results are routed to the appropriate team inbox within each customer organization based on configured escalation rules.
AvailableNo fix version has been published upstream for this CVE. HarborGuard re-checks the Patchstack advisory each ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix ships. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must be able to deliver a crafted URL to a victim who accesses the affected site over the network, making the service's public exposure a prerequisite.
- AuthenticationNot required
No account or credentials are needed; the attack is carried out by any unauthenticated party who can send a link to a victim.
- Victim interactionRequired
The victim must click or otherwise load the attacker-crafted URL, making social engineering or phishing a necessary step in the attack chain.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race conditions, or environmental factors to succeed.
Blast Radius
- Attacker script runs in the victim's browser session and can read session cookies or authentication tokens accessible to JavaScript on that origin.
- Injected script can modify page content seen by the victim, enabling phishing overlays or redirection to attacker-controlled sites.
- Browser-stored credentials or form data visible to the page context can be exfiltrated to an external endpoint.
- The affected page's functionality can be disrupted for the targeted user during the attack session.
How HarborGuard Handles This
Available on HarborGuard: this CVE is actively tracked against all images containing MagOne 9.0 or earlier, including internally built WordPress images. Because no upstream patch exists yet, HarborGuard monitors the Patchstack advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment a fix version is published. In the interim, customers can apply compensating controls through HarborGuard's policy engine, including network-policy rules that restrict unexpected outbound requests from web containers, egress filtering to block data exfiltration endpoints, and feature-flag gating to disable the vulnerable theme component if the platform supports it. For customers with auto-remediation enabled, once a fix ships the full flow (rebuild, regression test run, and PR opened against affected workloads) executes without manual steps.
- Sneeit / MagOne≤ 9.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L