CVE-2025-69096 describes a Reflected Cross-site Scripting (XSS) vulnerability (CWE-79) in G5Theme Zorka, affecting versions up to and including 1.5.7. Rated 7.1 HIGH on CVSS 3.1, this vulnerability allows an unauthenticated attacker to execute malicious scripts in a victim's browser via a network vector with low attack complexity, potentially impacting confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are public exploit modules available for Metasploit, Nuclei, or ExploitDB. The vulnerability is not listed in CISA's KEV catalog, has no reported media coverage or community discussion, and its extremely low EPSS score (0.00033) indicates a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| G5Theme | Zorka | >= 0, <= 1.5.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.