Impact
This vulnerability is an improper neutralization of input during web page generation, allowing an attacker to store malicious script content that is later executed by any user who views the affected page. The stored XSS payload can run arbitrary JavaScript in the victim’s browser, enabling session hijacking, defacement, or phishing. The weakness is a classic Cross‑Site Scripting flaw.
Affected Systems
The weakness affects the WordPress AuraMart theme produced by Techthemes, in all versions up to and including 2.0.7. Any WordPress installation that has not upgraded beyond this version is at risk.
Risk and Exploitability
Based on the description, it is inferred that exploitation likely requires an attacker who can submit or edit content that is stored and displayed by the theme, such as a user with administrative privileges or a vulnerable front‑end data entry point. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. No confirmed public exploits are known as of the data reported.
OpenCVE Enrichment
EUVD