Junglewise Threat Intelligence

CVE-2025-69104: jkdevstudio Qreatix unauthenticated XSS in WordPress theme

CVE-2025-69104 · Severity: high · CVSS 7.1 · Published 2026-06-17

Executive brief

The Qreatix theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks on a specially crafted link, the attacker could steal login sessions, redirect users to malicious websites, or deface the site. This affects the overall reputation and security of the website, potentially leading to unauthorized access.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Qreatix WordPress theme (versions <= 1.9.4) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is unauthenticated and can be triggered remotely; however, it requires user interaction, such as a victim clicking a malicious link. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch is available from the vendor.

Affected products

  • jkdevstudio Qreatix <= 1.9.4

Timeline

  • 2025-10-15: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD

References