MEDIUM
silverks
CVE published 2026-10-10
CVE-2026-17025
The Graphene theme for WordPress has a Stored Cross-Site Scripting vulnerability via 'Current location' and 'Author profile image URL' Profile Fields in versions up to and including 2.9.4. This allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts in pages that will execute when a user accesses an injected page.