VYPR
High severity7.1NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2025-69367

CVE-2025-69367

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through <= 4.4.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-based Cross-Site Scripting (XSS) in the GT3themes Oyster WordPress theme through version 4.4.3 allows attackers to inject malicious scripts via crafted user interactions.

Vulnerability

Overview

The GT3themes Oyster - Photography WordPress Theme is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack due to improper neutralization of user input during web page generation. This vulnerability affects all versions up to and including 4.4.3 [1].

Exploitation

Details

Exploitation requires user interaction, such as clicking a malicious link, visiting a crafted page, or submitting a specially prepared form. The attack can be initiated by an authenticated user with the required privilege level, leading to execution of malicious scripts within the context of the victim's browser session [1].

Impact

Successful exploitation allows an attacker to inject arbitrary HTML and JavaScript code into the website, which will execute when other users visit the affected pages. This can be used to redirect visitors, display unwanted advertisements, or steal sensitive information [1]. The vulnerability is considered moderately dangerous and is expected to be used in mass-exploit campaigns targeting thousands of sites regardless of traffic size [1].

Mitigation

Users are advised to update the theme to a patched version immediately. As of the publication date, a mitigation rule from Patchstack is available to block attacks until an official patch is released and safely applied. If immediate updating is not possible, users should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.