Oxygen - WooCommerce WordPress Theme

Oxygen - WooCommerce WordPress Theme has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 2 disclosures.

The most common weakness is Server-Side Request Forgery (SSRF), behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

2 independent researchers contributed these findings, one record each. Oxygen - WooCommerce WordPress Theme is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The upstream project has not shipped an update in about 10 years, so new fixes are unlikely to arrive on their own.

Strategic Overview

Avg CVSSHigh
7.2/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Oxygen - WooCommerce WordPress Theme vulnerabilities before they are exploited.

Most severe open issueCVSS 7.2CVE-2025-69299

Oxygen <= 6.0.8 - Unauthenticated Server-Side Request Forgery

Read the full analysis

Vulnerability Records

2 records
Oxygen screenshot
Latestv0.6.0
4.3(20)
86/100
Last Updated
2016-07-03 (10y ago)
Active Installs
2,000+
Downloads
403,371
Requires WP
0+
Requires PHP
0+
Created
2012-03-06 (15y ago)

Oxygen is a minimalistic, mobile-optimized magazine theme with responsive layout. The main features include a featured content slider, custom front page template, 5 widget areas, and 3 menus.

Tags
BlogGrid layoutPhotographyLeft sidebarMicroformatsRight sidebarThree columnsFooter widgetsFeatured imagesCustom backgroundThreaded commentsTranslation readyRTL language support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C