CVE-2025-69321: WordPress Grand Spa theme <= 3.5.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 22, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Spa grandspa allows Reflected XSS.This issue affects Grand Spa: from n/a through <= 3.5.5.
Affected Software
2 affected components
ThemeGoods Grand Spa<=3.5.5
wordpress/grand-spa<=3.5.5
Event History
Jan 22, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69321?
CVE-2025-69321 is classified as a reflected cross-site scripting (XSS) vulnerability which can allow attackers to inject malicious scripts into web pages.
2
How do I fix CVE-2025-69321?
To fix CVE-2025-69321, update the Grand Spa theme to version 3.5.6 or later.
3
Which versions of Grand Spa are affected by CVE-2025-69321?
CVE-2025-69321 affects Grand Spa theme versions up to and including 3.5.5.
4
What type of vulnerability is CVE-2025-69321?
CVE-2025-69321 is a reflected cross-site scripting (XSS) vulnerability.
5
Who is the vendor of the software affected by CVE-2025-69321?
The vendor of the affected software, Grand Spa theme, is ThemeGoods.