Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

Oxygen Theme for WordPress allows attackers to access internal services

CVE-2025-12886
Summary

The Oxygen Theme for WordPress is at risk because an attacker can use it to access and modify internal services without permission. This could lead to sensitive information being exposed or changed. Update the theme to a secure version as soon as possible to protect your site.

Original title
The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for un...
Original description
The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
nvd CVSS3.1 7.2
Vulnerability type
CWE-918 Server-Side Request Forgery (SSRF)
Published: 28 Mar 2026 · Updated: 28 Mar 2026 · First seen: 28 Mar 2026