WordPress security by component
Oxygen - WooCommerce WordPress Theme
Oxygen - WooCommerce WordPress Theme (oxygen-theme) is a WordPress theme with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 28, 2026; the highest published CVSS base score is 7.2.
Theme slug:
oxygen-themeLatest vulnerability
CVE-2025-12886: Oxygen - WooCommerce WordPress Theme: Server-side request forgery
Oxygen - WooCommerce WordPress Theme is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 6.0.8.
| Safe version |
|
||
|---|---|---|---|
| Mar 28, 2026 |
CVE-2025-12886
Oxygen - WooCommerce WordPress Theme: Server-side request forgery
Oxygen - WooCommerce WordPress Theme is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 6.0.8.
|
See mitigation notes |
CVE7.2
NVDPending
|