🔐 CVE Alert

CVE-2025-69299

HIGH 7.2

WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a through <= 6.0.8.

CWE CWE-918
Vendor laborator
Product oxygen
Published Feb 20, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for laborator oxygen

Be the first to know when new high vulnerabilities affecting laborator oxygen are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Laborator / Oxygen
0 ≤ 6.0.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Theme/oxygen/vulnerability/wordpress-oxygen-theme-6-0-8-server-side-request-forgery-ssrf-vulnerability?_s_id=cve

Credits

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program