PatchSiren

WEN Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WEN Themes CVE published 2026-05-07

CVE-2025-62127

A Cross-site Scripting (XSS) vulnerability exists in the WEN Logo Slider plugin for WordPress, affecting versions from n/a through 3.4.0. This issue allows for DOM-Based XSS, with a CVSS score of 5.9 and a severity of MEDIUM. Defenders responsible for WordPress environments using the WEN Logo Slider plugin should assess exposure and prioritize verification and potential updates. The vulnerability has been [truncated]