Impact
The vulnerability arises from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary JavaScript into the rendered page. This may permit malicious code execution within a visitor's browser.
Affected Systems
The flaw affects the Asmedia Tuaug4 WordPress theme in all releases up through version 1.4. Any website that has installed this theme, regardless of its WordPress core version, is potentially vulnerable unless the theme has been updated beyond the specified boundary.
Risk and Exploitability
Based on the description, it is inferred that the attack vector involves injecting malicious input that is reflected in the response, enabling client‑side script execution. The CVSS score of 7.1 indicates medium‑to‑high severity, and the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation. The flaw is not listed in the KEV catalog.
OpenCVE Enrichment
EUVD