Oxygen - WooCommerce WordPress Theme
Oxygen - WooCommerce WordPress Theme has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 2 disclosures.
The most common weakness is Server-Side Request Forgery (SSRF), behind 2 of the records (100%).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. Oxygen - WooCommerce WordPress Theme is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 10 years, so new fixes are unlikely to arrive on their own.
CVE-2025-69299Oxygen <= 6.0.8 - Unauthenticated Server-Side Request Forgery
Read the full analysisVulnerability Records

Oxygen
Author
Griden
Oxygen is a minimalistic, mobile-optimized magazine theme with responsive layout. The main features include a featured content slider, custom front page template, 5 widget areas, and 3 menus.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C