CVE-2026-0867 | catchthemes Essential Widgets Plugin up to 3.0 on WordPress ew-author/ew-archive/ew-category/ew-page/ew-menu cross site scripting
A vulnerability, which was classified as problematic, has been found in catchthemes Essential Widgets Plugin up to 3.0 on WordPress. The affected element is the function ew-author/ew-archive/ew-category/ew-page/ew-menu. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-0867. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.