CVE-2026-62098MEDIUM NVDCVSS Score 6.5Severity MEDIUMPublished Oct 10, 2026Vendor unknownDescriptionUnauthenticated Content Injection in Boutique <= 2.3.3 versions.Referenceshttps://patchstack.com/database/wordpress/theme/kute-boutique/vulnerability/wordpress-boutique-theme-2-3-3-arbitrary-shortcode-execution-vulnerability?_s_id=cve