Impact
The WordPress theme for Dream‑Theme contains a stored cross‑site scripting flaw in the ‘the7_fancy_title_css’ parameter. Unsanitized input allows an attacker who can log in as a Contributor or higher to inject arbitrary JavaScript that will execute whenever a victim views an affected page. This capability can enable defacement, credential theft, session hijacking, or other client‑side compromise actions. The vulnerability is a classic input validation weakness (CWE‑79).
Affected Systems
All releases of Dream‑Theme’s The7 theme through version 12.9.1, including all earlier builds, are susceptible.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate severity. EPSS indicates an exploitation probability of less than 1 %. The exploit requires authenticated access with Contributor privileges and the ability to modify theme settings, so it may not be widely available to anonymous attackers. The vulnerability is not in CISA’s KEV catalog, suggesting that mass‐deployment of attack code has not been observed yet.
OpenCVE Enrichment