Impact
The vulnerability is an improper neutralization of user input during web page generation, classified as CWE‑79. An attacker can craft a URL that includes malicious script which, when visited by a victim, will be executed in the victim’s browser. This can enable the attacker to steal session cookies, deface content, or upload additional malware, compromising the confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The duwasai Flashy theme, versions up through 1.2.1, is vulnerable. Any WordPress installation that includes Flashy 1.2.1 or an earlier release is at risk. The description does not specify a minimum affected version, so all prior releases should be considered vulnerable.
Risk and Exploitability
With a CVSS score of 7.1 this issue falls into the high severity range. The EPSS score of less than 1 % suggests that exploitation is unlikely to be widespread. The vulnerability is reflected; attackers must entice victims to visit crafted links or embed malicious parameters, meaning successful exploitation requires successful social engineering. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD