CVE-2025-67952: WordPress Grand Tour theme < 5.6.2 - Cross Site Scripting (XSS) vulnerability
Published Jan 22, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Tour grandtour allows Reflected XSS.This issue affects Grand Tour: from n/a through < 5.6.2.
Affected Software
1 affected component
ThemeGoods Grand Tour<5.6.2
Event History
Jan 22, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67952?
CVE-2025-67952 is classified as a high severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-67952?
To resolve CVE-2025-67952, update the WordPress Grand Tour theme to version 5.6.2 or higher.
3
What type of vulnerability is CVE-2025-67952?
CVE-2025-67952 is a Cross Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
4
Which software is affected by CVE-2025-67952?
CVE-2025-67952 affects the Grand Tour theme by ThemeGoods, specifically versions prior to 5.6.2.
5
Can CVE-2025-67952 lead to data theft?
Yes, CVE-2025-67952 can potentially lead to data theft by allowing attackers to manipulate input/output and execute harmful scripts.