CVE-2025-15688: WordPress Capella theme <= 2.5.5 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Affected Software
1 affected component
WordPress Capella theme<=2.5.5
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation.
2
Which installations are affected?
Capella theme versions 2.5.5 and earlier are affected according to the available data. The information provided does not state whether any particular theme configuration is required.
3
What is the likely impact of successful exploitation?
The supplied severity vector indicates network-reachable exploitation with low attack complexity, no privileges, and no user interaction. It indicates high confidentiality impact and low availability impact; integrity impact is listed as none.