Impact
The vulnerability stems from improper neutralization of user input during page generation, allowing an attacker to inject arbitrary JavaScript that is executed in the web browser of anyone who views a crafted page. This can be used to steal session cookies, deface the site, or perform phishing attacks within the victim’s session. The weakness is categorized as CWE‑79, reflecting a classic reflected XSS flaw.
Affected Systems
WordPress users who have installed the Polka Dots theme from fyrewurks at any version up to and including 1.2 are impacted. Any site that has not yet moved beyond version 1.2 remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate-to-high risk, and the EPSS score of less than 1% suggests that few exploits are publicly available yet, though the flaw is still actionable. The vulnerability is not listed in the CISA KEV catalog, but the low exploitation probability does not preclude targeted attacks via email or social engineering that embed malicious URLs. Exploitation typically requires a user to click a crafted link or enter data that the theme reflects unescaped; no privileged access or additional software is needed.
OpenCVE Enrichment
EUVD