Stored Cross-Site Scripting Vulnerability in Graphene Theme for WordPress
CVE-2026-17025
6.4MEDIUM
What is CVE-2026-17025?
The Graphene theme for WordPress is affected by a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping. This flaw allows authenticated attackers with Subscriber-level access or higher to insert malicious web scripts into profile fields such as 'Current location' and 'Author profile image URL'. When other users access these compromised pages, the injected scripts can execute, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
Graphene 0 <= 2.9.4