Impact
Improper neutralization of user input during web page generation results in a DOM‑based cross‑site scripting vulnerability. An attacker can inject arbitrary JavaScript that executes in the browsers of visitors who load affected pages, potentially compromising user data, session tokens, or delivering phishing payloads. The weakness is classified as CWE‑79 – Improper Neutralization of Input During Web Page Generation.
Affected Systems
The vulnerability affects the WordPress City Store theme supplied by yudleethemes. All released versions up to and including 1.4.5 are impacted, as the issue exists from the earliest available release through 1.4.5.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate complexity and potential impact. The EPSS score of less than 1% suggests a low probability of active exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be DOM‑based, likely triggered by malicious users injecting script into data fields that the theme outputs directly into the page—such as custom widget text or other user‑editable content. The exploitation does not require elevated privileges or special network access; it depends on the victim viewing a compromised page.
OpenCVE Enrichment
EUVD