CVE-2025-69154: Designthemes Spalab | Beauty Salon WordPress Theme

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.

Affected products

  • Designthemes Spalab | Beauty Salon WordPress Theme: up to and including 6.7

Published 2026-07-02. Last modified 2026-10-06.