Impact
The Open Source Genesis Framework theme for WordPress is vulnerable to stored cross‑site scripting because shortcodes accept user‑supplied attributes that are neither sanitized nor properly escaped. An attacker who holds a contributor‑level or higher account can embed arbitrary JavaScript into page content through these shortcodes, and the injected script executes whenever another visitor opens the affected page.
Affected Systems
All releases of the StudioPress Open Source Genesis Framework up to and including version 3.6.0 are affected. WordPress sites that deploy this theme and allow contributors to edit or insert shortcode content are at risk.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate severity, while the EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at the time of this review. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. Exploitation requires an authenticated contributor‑level account, and the attacker can then place malicious scripts that run for any user who views pages containing the affected shortcodes.
OpenCVE Enrichment