CVE-2025-64207: WordPress Jannah theme <= 7.6.0 - Cross Site Scripting (XSS) vulnerability
Published Dec 18, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah jannah allows DOM-Based XSS.This issue affects Jannah: from n/a through <= 7.6.0.
Affected Software
2 affected components
Tielabs Jannah<=7.6.0
WordPress Jannah<=7.6.0
Event History
Dec 18, 2025
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64207?
CVE-2025-64207 is classified as a high-severity vulnerability due to its potential for DOM-Based Cross-site Scripting.
2
How do I fix CVE-2025-64207?
To fix CVE-2025-64207, update the TieLabs Jannah theme to the latest version beyond 7.6.0.
3
Who is affected by CVE-2025-64207?
CVE-2025-64207 affects users of TieLabs Jannah theme versions up to and including 7.6.0.
4
What kind of attacks can be executed due to CVE-2025-64207?
Attackers can exploit CVE-2025-64207 to perform Cross-site Scripting (XSS) attacks, potentially compromising user data.
5
Is CVE-2025-64207 found in multiple platforms?
Yes, CVE-2025-64207 is present in both the TieLabs Jannah and WordPress Jannah themes.