Sceawere

Vulnerability Detail

CVE-2026-17025UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Graphene Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
silverks
Product
Graphene
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T06:16:42.240Z",
  "pubdate": "2026-10-10T06:16:42.240Z",
  "executiveSummary": "The Graphene theme for WordPress, in versions up to and including 2.9.4, contains a critical security flaw categorized as a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability exists within the 'Current location' and 'Author profile image URL' profile fields, which fail to implement adequate input sanitization and output escaping mechanisms.\nThe flaw allows authenticated users with Subscriber-level privileges or higher to inject malicious JavaScript payloads into their user profiles.\nOnce stored, these scripts execute within the context of the victim's browser session whenever an affected page is rendered, potentially leading to unauthorized actions, session hijacking, or the defacement of administrative interfaces.\nThe risk is significant due to the ability of attackers to target higher-privileged users, such as administrators, who may view the compromised profile information, effectively escalating the impact of the initial access.",
  "technicalDetails": "The root cause of this vulnerability is the improper handling of user-supplied data within the Graphene theme's profile management functionality. Specifically, the theme fails to validate or sanitize inputs provided in the 'Current location' and 'Author profile image URL' fields before storing them in the WordPress database.\nFurthermore, the theme exhibits a lack of context-aware output escaping when rendering these profile fields on the front-end or within the dashboard. This creates a Stored XSS condition where the browser interprets injected script tags as legitimate executable code rather than plain text.\nThe attack flow begins when an authenticated user (Subscriber or higher) navigates to their profile settings. The attacker submits a malicious payload—such as '<script>alert(document.cookie)</script>'—into the vulnerable input fields. The application saves this malicious string directly into the wp_usermeta table without transformation.\nWhenever a legitimate user or administrator views a page where this profile metadata is subsequently rendered, the server transmits the raw, malicious payload to the victim's browser. The browser, failing to find sufficient security controls, executes the JavaScript in the security context of the target's current session.\nThis behavior facilitates a range of post-exploitation activities, including, but not limited to, the theft of session tokens (session hijacking), unauthorized administrative actions performed on behalf of the victim (CSRF-like behavior), and the redirection of users to malicious third-party domains.\nBecause the theme logic fails to enforce input validation at the point of entry and output encoding at the point of presentation, the vulnerability remains persistent and globally effective for any user who interacts with the compromised profile metadata.\nThe scope of this vulnerability covers all Graphene theme installations up to and including version 2.9.4. No specific network-level exposure is required beyond the attacker maintaining a standard subscriber account on the target WordPress instance, making this a high-impact security risk for multi-user WordPress environments."
}
CVE-2026-17025: Graphene Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.4) | Sceawere