CVE-2025-12886Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-28); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-28: 4Mentions · 2026-05-02: 1Patch / Workaround · 2026-05-02: 1Technical Details · 2026-03-28: 3Technical Details · 2026-05-02: 103-2805-02
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-284
Disclosure4
2026-05-021
Patch1
Full discourse5 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    Oxygen Theme WP <=6.0.8: Unauth SSRF in laborator_calc_route AJAX. No URL validation, hit cloud metadata or internals. CVSS 7.2. Patch it. #SSRF #WordPress #DevSecOps #CVE #infosec #developers Info: https://www.valtersit.com/cve/2026/03/cve-2025-12886/

    Post summary

    The post highlights an unauthenticated SSRF flaw in Oxygen Theme WP (<=6.0.8) with CVSS 7.2 and urges users to apply the available patch.

    00000189
    889 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-12886 - Oxygen &amp;lt;= 6.0.8 - Unauthenticated Server-Side Request Forgery via route_path Intel Report: https://ift.tt/LA3gZm8

    Post summary

    An unauthenticated server‑side request forgery vulnerability (CVE‑2025‑12886) affects Oxygen as far back as version 6.0.8, announced in a threat alert with an intel link, but no PoC, exploit, or patch details are provided.

    00000120
    283 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-12886 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-12886 #CVE-2025-12886 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/yL3dugCOqu

    Post summary

    The post announces CVE-2025-12886 as a high‑risk vulnerability affecting WordPress with a severity score of 7.2, but offers no additional technical details, PoC, patches, or exploitation information.

    00000122
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-12886 - Oxygen &amp;lt;= 6.0.8 - Unauthenticated Server-Side Request Forgery via route_path Intel Report: https://ift.tt/nxbrtdI

    Post summary

    The tweet announces the CVE‑2025‑12886 vulnerability in Oxygen <=6.0.8, highlighting an unauthenticated server‑side request forgery via route_path and links to an Intel report for more details.

    00000127
    283 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-12886 The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action… https://www.cve.org/CVERecord?id=CVE-2025-12886

    Post summary

    The text announces the discovery of an SSRF vulnerability in the Oxygen Theme WordPress plugin, detailing affected versions without mentioning patches or exploitation activity.

    00000159
    56.9K followersView on X

Explore more