Impact
The jinwen Js O3 Lite theme includes an improper neutralization of input flaw that permits reflected XSS. When a browser renders a page that incorporates user‑supplied data without proper escaping, an attacker can inject executable script. This can lead to cookie theft, session hijacking, or defacement of the site – a classic CWE‑79 weakness.
Affected Systems
Any WordPress installation that uses the Js O3 Lite theme version 1.5.8.2 or earlier is vulnerable. The issue applies to all releases from the earliest available version up to 1.5.8.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that, at present, exploitation attempts are rare, but the vulnerability remains usable by a remote attacker who can craft a malicious link or embedded request. The vulnerability is not listed in the CISA KEV catalog, so no high‑profile exploits are known yet. Attackers would need to coerce a legitimate user to visit a URL that triggers the reflected XSS, making the threat primarily a social‑engineering risk.
OpenCVE Enrichment
EUVD