Junglewise Threat Intelligence

CVE-2025-15688: WordPress Capella Theme SQL injection

CVE-2025-15688 · Severity: critical · CVSS 9.3 · Published 2026-08-20

Executive brief

WordPress Capella Theme is a popular website design template used to build and manage website appearance and layout. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete an entire website database including user accounts, passwords, and customer data without any special access or authentication.

Technical details

This is an unauthenticated SQL injection vulnerability in the WordPress Capella Theme (versions <= 2.5.5). The vulnerability allows attackers to inject arbitrary SQL commands through user-controlled input without requiring authentication or prior access to the system. By exploiting this flaw, attackers can fully compromise the website database—reading sensitive data, modifying records, or deleting content entirely. The vulnerability is reachable over the network and requires no user interaction. As of the advisory date, no official patch is available; vendors recommend updating to a patched version when available or implementing WAF rules to block exploitation attempts.

Affected products

  • Capella Capella Theme <= 2.5.5

Timeline

  • 2026-08-20: disclosed: Vulnerability disclosed and published on NVD and Patchstack
  • 2026-01-05: other: Vulnerability reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) to Patchstack

References