Impact
The StorePress theme contains a DOM-based cross‑site scripting flaw due to improper neutralization of input during web page generation. When user‑supplied data is inserted into the page without adequate escaping, an attacker can inject malicious JavaScript that runs in the victim’s browser. This flaw can be used to steal session cookies, deface content, or hijack user sessions, affecting the confidentiality, integrity, and availability of user data.
Affected Systems
WordPress users deploying the vfthemes StorePress theme version 1.0.12 or earlier are affected. This vulnerability does not apply to releases newer than 1.0.12, which presumably contain the fix.
Risk and Exploitability
With a CVSS score of 6.5 the weakness scores as moderate severity, and an EPSS score of less than 1 % indicates that the industry estimates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale public exploitation. The likely attack vector is DOM‑based XSS, which typically requires an attacker to convince a user to visit a crafted URL or submit a malicious form, causing the injected script to execute in the victim’s browser.
OpenCVE Enrichment
EUVD