PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17025 silverks CVE debrief

The Graphene theme for WordPress has a Stored Cross-Site Scripting vulnerability via 'Current location' and 'Author profile image URL' Profile Fields in versions up to and including 2.9.4. This allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts in pages that will execute when a user accesses an injected page.

Vendor
silverks
Product
Graphene
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and administrators of WordPress sites using the Graphene theme should assess exposure and prioritize updates to prevent exploitation. This includes reviewing current theme versions, restricting access where necessary, and monitoring for suspicious activity. Security teams and vulnerability management teams should also review and act on this vulnerability to prevent potential script injections.

Why it matters

The Graphene theme for WordPress has a Stored Cross-Site Scripting vulnerability, allowing authenticated attackers to inject arbitrary web scripts. Defenders should prioritize verifying and updating Graphene theme versions to prevent exploitation.

  • Potential injection of arbitrary web scripts in pages
  • Execution of injected scripts when users access affected pages
  • Possible compromise of user sessions or sensitive data
  • Verification of Graphene theme versions and updates required

Technical summary

The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts in pages that will execute when a user accesses an injected page. The vulnerability is confirmed through CVE Program and NVD records, highlighting the need for defenders to prioritize verifying and updating Graphene theme versions.

Defensive priority

Defenders should prioritize verifying and updating Graphene theme versions to prevent exploitation.

Recommended defensive actions

  • Verify and update Graphene theme versions to 2.9.5 or later
  • Restrict Subscriber-level access and above to prevent exploitation
  • Monitor for suspicious page accesses and script injections
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed in Graphene theme versions up to 2.9.4. The CVE Program and NVD provide official records and assessments. Defenders should verify the Graphene theme version and review profile fields for potential script injection. Evidence limits suggest focusing on confirmed versions and CVE details. Official records indicate a Stored Cross-Site Scripting vulnerability via 'Current location' and 'Author profile image URL' Profile Fields.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17025 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17025

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17025 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17025

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.