Executive brief
The SpaLab theme for WordPress, commonly used by beauty salons and wellness centers, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks on a specially crafted link, the attacker could potentially hijack their session, redirect users to malicious websites, or deface the site. This vulnerability is particularly risky because it does not require the attacker to have an account on the site.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the SpaLab | Beauty Salon WordPress theme through version 6.7 due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into interacting with a malicious link or page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the latest advisory, no official patch has been released, though third-party mitigation rules are available.
Affected products
- designthemes SpaLab | Beauty Salon WordPress Theme <= 6.7
Timeline
- 2025-11-07: disclosed: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-06-30: advisory: Patchstack published the vulnerability details
- 2026-07-02: advisory: CVE published in the National Vulnerability Database (NVD)