Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that results in Reflected Cross‑Site Scripting. A crafted URL can inject malicious JavaScript that executes in the context of an affected visitor’s browser, potentially allowing session hijacking, credential theft, or defacement.
Affected Systems
The issue affects the WordPress Tiki Time theme released by fyrewurks, versions up through and including 1.3. Any site that has installed or activated this theme is impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates a low likelihood of active exploitation, and the vulnerability is not registered in CISA’s KEV catalog. The attack vector is inferred to be a reflected XSS attack delivered via malicious links or search results, exploiting user input that is not properly encoded before rendering in a response.
OpenCVE Enrichment
EUVD