CVE-2025-59560: WordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerability
Published Jun 17, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
Affected Software
1 affected component
Sonaar Sonaar WordPress Theme<=4.27.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Sonaar themeto a version that resolves this vulnerability.Fixed in 4.27.5
Event History
Jun 17, 2026
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-59560?
CVE-2025-59560 has a high severity rating of 7.1.
2
How do I fix CVE-2025-59560?
To fix CVE-2025-59560, update the Sonaar theme to a version greater than 4.27.4.
3
What type of vulnerability is CVE-2025-59560?
CVE-2025-59560 is a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2025-59560?
CVE-2025-59560 affects users of the Sonaar WordPress theme version 4.27.4 and earlier.
5
Is authentication required to exploit CVE-2025-59560?
No, CVE-2025-59560 can be exploited without authentication.