Impact
The Angel – Fashion Model Agency WordPress CMS Theme is vulnerable to a stored cross‑site scripting flaw in the profile media uploader. An attacker who is authenticated with subscriber‑level or higher privileges can embed arbitrary scripts that will run in the browsers of any user who views pages containing the injected media. This allows the attacker to hijack users’ sessions, steal credentials, or deface the site, thereby compromising the confidentiality, integrity, and availability of the application.
Affected Systems
The vulnerability affects installations of the kayapati:Angel – Fashion Model Agency WordPress CMS Theme in all releases up to and including version 3.2.3. Any site still running a pre‑3.2.4 build of the theme is susceptible, regardless of the presence or absence of other security controls.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation at the time of reporting. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker can access the profile media upload form—a permission normally granted to subscribers or higher users. Thus, sites that broadly allow subscriber‑level users to upload media are at elevated risk, whereas environments that restrict this capability to administrators have a reduced attack surface.
OpenCVE Enrichment