Cross-site Scripting Vulnerability in Rehub Theme by Sizam
CVE-2025-64197

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-64197?

The Rehub theme developed by Sizam is susceptible to a Cross-site Scripting (XSS) vulnerability that allows an attacker to inject malicious scripts into web pages. This flaw enables stored XSS attacks, where user data is compromised when the injected script is executed in the context of a victim's browser. Affected versions prior to 19.9.9.1 may expose users to significant risks, emphasizing the need for timely updates to mitigate this security threat.

Affected Version(s)

Rehub <= n/a

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.