HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-39548Published Modified CNA Patchstack

CVE-2026-39548: WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Reflected cross-site scripting (XSS) vulnerability affects the MagOne WordPress theme by Sneeit in versions 9.0 and earlier. An unauthenticated attacker can deliver a malicious link to a victim over the network, and when the victim clicks it, the attacker's script executes inside the victim's browser session on the affected site. Successful exploitation lets an attacker read browser-accessible data such as session cookies, inject content into the page, and trigger minor disruption of the user's experience. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment an upstream fix is published.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds including Patchstack within minutes of publication and matched against customer images, including custom-built images that bundle the MagOne theme. Any image carrying MagOne 9.0 or earlier is flagged automatically.

Available
Triage

HarborGuard scores this finding at CVSS 7.1 (High) and weights it against each environment's compliance policy to determine urgency and ownership. Triage results are routed to the appropriate team inbox within each customer organization based on configured escalation rules.

Available
Patch

No fix version has been published upstream for this CVE. HarborGuard re-checks the Patchstack advisory each ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix ships. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to deliver a crafted URL to a victim who accesses the affected site over the network, making the service's public exposure a prerequisite.

  • AuthenticationNot required

    No account or credentials are needed; the attack is carried out by any unauthenticated party who can send a link to a victim.

  • Victim interactionRequired

    The victim must click or otherwise load the attacker-crafted URL, making social engineering or phishing a necessary step in the attack chain.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race conditions, or environmental factors to succeed.

Blast Radius

  • Attacker script runs in the victim's browser session and can read session cookies or authentication tokens accessible to JavaScript on that origin.
  • Injected script can modify page content seen by the victim, enabling phishing overlays or redirection to attacker-controlled sites.
  • Browser-stored credentials or form data visible to the page context can be exfiltrated to an external endpoint.
  • The affected page's functionality can be disrupted for the targeted user during the attack session.

How HarborGuard Handles This

Available on HarborGuard: this CVE is actively tracked against all images containing MagOne 9.0 or earlier, including internally built WordPress images. Because no upstream patch exists yet, HarborGuard monitors the Patchstack advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment a fix version is published. In the interim, customers can apply compensating controls through HarborGuard's policy engine, including network-policy rules that restrict unexpected outbound requests from web containers, egress filtering to block data exfiltration endpoints, and feature-flag gating to disable the vulnerable theme component if the platform supports it. For customers with auto-remediation enabled, once a fix ships the full flow (rebuild, regression test run, and PR opened against affected workloads) executes without manual steps.

See how HarborGuard automates this
Affected packages
  • Sneeit / MagOne
    ≤ 9.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
References