Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw caused by the Store Commerce WordPress theme’s failure to neutralize user‑supplied input during page generation. When data is rendered into the page’s Document Object Model without proper escaping, an attacker can inject and execute arbitrary JavaScript in anyone who loads the affected page, potentially exposing information or hijacking the browsing session.
Affected Systems
Installations of athemeart’s Store Commerce WordPress theme version 1.2.3 and earlier are vulnerable; later releases do not contain the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not catalogued in CISA KEV. Exploitation requires a web‑based attack vector that delivers crafted input rendered by the theme; no privileged or remote system access is necessary.
OpenCVE Enrichment
EUVD