Impact
The vulnerability in the DWT Directory & Listing WordPress Theme allows authenticated users with contributor‑level or higher permissions to inject arbitrary JavaScript through shortcodes because the theme does not properly sanitize or escape user‑supplied attributes. When a malicious script is stored in this manner, it executes in the browser of any visitor who loads the affected page, potentially allowing the attacker to steal session cookies, deface content, or perform phishing attacks. The underlying flaw is a typical improper input validation weakness (CWE‑79).
Affected Systems
WordPress sites that have installed the DWT Directory & Listing WordPress Theme in versions up to and including 3.3.4, purchased from ThemeForest. These sites are vulnerable regardless of the rest of the theme or WordPress core version, provided the vulnerable shortcodes remain active.
Risk and Exploitability
The CVSS base score is 6.4, indicating medium severity. The EPSS score shows a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been observed in active exploitation. Attackers must possess at least contributor privileges to inject the payload, and the injected script will affect all subsequent visitors to the impacted page. No public exploit has been documented, but the flaw’s nature means it could be leveraged fairly easily if a patch is not applied.
OpenCVE Enrichment
EUVD