Description
Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into a visitor’s browser when the SpaLab theme is used. The weakness is a classic input‑validation error identified as CWE‑79.

Affected Systems

The flaw affects installations of the Designthemes SpaLab Beauty Salon WordPress Theme with versions 6.7 and earlier. Any WordPress site deploying this theme without an upgrade is susceptible, regardless of the underlying WordPress core version.

Risk and Exploitability

The CVSS score for this vulnerability is 7.1. EPSS indicates a very low exploitation probability (< 1%). Based on the description, the likely attack vector is that an attacker can exploit the flaw simply by directing a user to site or crafting that leads a visitor to the vulnerable theme. Because the flaw is client‑side and does not require authentication, anyone visiting the site is at risk. The vulnerability is not listed in the CISA KEV catalog, which indicates no known widespread exploitation reports.

Generated by OpenCVE AI on July 21, 2026 at 12:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SpaLab theme to a version newer than 6.7, which contains the patch for the XSS flaw.
  • If an update is not immediately available, disable or replace the vulnerable theme to prevent user exposure.
  • Apply a Content Security Policy that disallows inline scripts and restricts script sources to trusted origins.

Generated by OpenCVE AI on July 21, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes spalab | Beauty Salon Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes spalab | Beauty Salon Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
Title WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Designthemes Spalab | Beauty Salon Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:54:49.155Z

Reserved: 2025-12-29T11:19:54.137Z

Link: CVE-2025-69154

cve-icon Vulnrichment

Updated: 2026-07-02T14:54:44.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')