<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Oxygen-Theme — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/oxygen-theme/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 28 Mar 2026 04:16:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/oxygen-theme/feed.xml" rel="self" type="application/rss+xml"/><item><title>Oxygen Theme WordPress Plugin Vulnerable to Server-Side Request Forgery (CVE-2025-12886)</title><link>https://feed.craftedsignal.io/briefs/2026-03-oxygen-theme-ssrf/</link><pubDate>Sat, 28 Mar 2026 04:16:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-oxygen-theme-ssrf/</guid><description>The Oxygen Theme for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to 6.0.8, allowing unauthenticated attackers to make arbitrary web requests via the laborator_calc_route AJAX action.</description><content:encoded>&lt;p>The Oxygen Theme WordPress plugin, versions 6.0.8 and earlier, contains a Server-Side Request Forgery (SSRF) vulnerability (CVE-2025-12886). This flaw allows unauthenticated attackers to send crafted requests to the WordPress server, potentially forcing it to make outbound connections to internal or external resources. The vulnerability is located within the &lt;code>laborator_calc_route&lt;/code> AJAX action. By exploiting this, attackers can potentially access sensitive internal resources, bypass firewall…&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>wordpress</category><category>oxygen-theme</category><category>cve-2025-12886</category></item></channel></rss>