Server-Side Request Forgery Vulnerability in Ona Theme for WordPress
CVE-2026-6812

4.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 May 2026

What is CVE-2026-6812?

The Ona theme for WordPress possesses a vulnerability that allows authenticated users with administrator-level access to perform Server-Side Request Forgery (SSRF) attacks. This flaw exists in the ona_activate_child_theme function and affects all versions up to, and including, 1.26. By exploiting this vulnerability, attackers could initiate web requests to arbitrary internal resources from the affected application, which could lead to unauthorized data queries and potential modification of sensitive information from internal services.

Affected Version(s)

Ona 0 <= 1.26

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Truong
.