PatchSiren

silverks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM silverks CVE published 2026-10-10

CVE-2026-17025

The Graphene theme for WordPress has a Stored Cross-Site Scripting vulnerability via 'Current location' and 'Author profile image URL' Profile Fields in versions up to and including 2.9.4. This allows authenticated attackers with Subscriber-level access and above to inject arbitrary web scripts in pages that will execute when a user accesses an injected page.