Impact
The Education LMS theme contains a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. An attacker can persist malicious script in the site’s content, and that script will execute in the browsers of any visitor who loads the affected page.
Affected Systems
All installations of the FilaThemes Education LMS theme with version 0.0.7 or earlier are vulnerable. Any WordPress site whose theme directory includes a copy of those versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity level, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would occur when an attacker injects script into the theme’s content stores, after which the script is rendered client‑side to every user who visits the relevant pages. No privileged access is necessary for exploitation.
OpenCVE Enrichment
EUVD