Impact
The vulnerability is an improper neutralization of input during web page generation, also known as Cross‑Site Scripting. It allows an attacker to inject malicious scripts that are reflected to the browser of a victim who visits a crafted URL that the moseter theme renders. This can enable attackers to steal session cookies, deface websites, or conduct further phishing or credential‑stealing operations.
Affected Systems
The issue affects the asmedia moseter WordPress theme in all versions up to 1.3.1. Users who are still running 1.3.1 or any earlier release of the theme are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential for exploitation. The EPSS score of less than 1% demonstrates a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote and can be performed via a simple HTTP request to any page that renders the vulnerable theme. The flaw does not require authentication or privileged access and can affect any visitor who receives the reflected script.
OpenCVE Enrichment
EUVD