
CVE-2026-6812 The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it poss… https://www.cve.org/CVERecord?id=CVE-2026-6812
Post summary
The post discloses that the Ona WordPress theme versions up to 1.26 are vulnerable to SSRF via the ona_activate_child_theme function, with no evidence of an active exploit, PoC, patch, or false‑positive statement.



