What is CVE-2026-8167?
CVE-2026-8167 is a Reflected XSS (Cross-site Scripting) vulnerability found in THEWP Digital Solutions' News Theme V8, caused by improper neutralization of input during web page generation. It affects versions through 16.06.2026, potentially allowing attackers to execute malicious scripts. Users should immediately update the theme to the latest secured version.
Azərbaycanca: CVE-2026-8167, THEWP Digital Solutions şirkətinin News Theme V8 məhsulunda aşkarlanmış Reflected XSS (Cross-site Scripting) zəifliyidir. Bu boşluq veb səhifənin yaradılması zamanı daxilolmaların düzgün neytrallaşdırılmaması nəticəsində yaranır və 16.06.2026 tarixinə qədər olan versiyalara təsir edir. Təhlükəsizliyi təmin etmək üçün tema dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which product does CVE-2026-8167 affect and what is the vulnerability type?
CVE-2026-8167 is a Reflected XSS (Cross-site Scripting) vulnerability found in THEWP Digital Solutions' News Theme V8.
What should users do to protect against this vulnerability?
Users should immediately update the theme to the latest secured version to ensure safety.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.