Impact
The newseqo WordPress theme contains an improper neutralization of user input during web page generation, enabling stored cross‑site scripting. A malicious actor can embed JavaScript code that will execute in the browsers of any user who views a page generated by the theme, potentially stealing session cookies, defacing site content, or redirecting users to phishing sites. This weakness is a classic stored XSS flaw as identified by CWE‑79.
Affected Systems
All installations of the newseqo theme built by themefunction are affected when the version is 2.1.1 or earlier. There are no known workarounds, and all known affected versions are listed in the CNA record from n/a through 2.1.1.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the moment, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector involves an authenticated user inserting malicious payloads into the theme’s configuration pages or content fields; the payload is stored server‑side and subsequently rendered without proper escaping.
OpenCVE Enrichment
EUVD