Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing a stored XSS flaw in the MorningTime Lite WordPress theme. An attacker who can insert content via the theme (for example through post or comment fields) can embed malicious JavaScript that will execute in the browsers of anyone viewing pages rendered with the vulnerable theme. This can lead to session hijacking, defacement, or delivery of malware and can compromise the confidentiality and integrity of user sessions.
Affected Systems
The affected product is the WordPress MorningTime Lite theme developed by victortihai. All releases from the earliest available version up to and including 1.3.2 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity for this stored XSS flaw. The EPSS score of less than 1% suggests a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely through a site‑wide input mechanism that accepts unsanitized content, such as a theme configuration or content editor that is accessible to authenticated users.
OpenCVE Enrichment
EUVD