Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress electrician allows Reflected XSS.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 1.0.
Published: 2025-07-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation creates a reflected XSS flaw that allows an attacker to inject malicious scripts through user input fields handled by the Electrician theme. Because the vulnerability lies in output escaping, an attacker could run arbitrary JavaScript in the victim’s browser, potentially stealing session cookies, defacing content, or redirecting users to phishing sites. The weakness is classified as CWE‑79.

Affected Systems

The Electrician – Electrical Service WordPress theme from vergatheme, any version from not otherwise specified up to and including 1.0, is affected. Any WordPress installation using this theme within that version range is susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity with potential impact on confidentiality, integrity, and availability through client‑side attacks. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog, reducing immediate systemic threat. However, because the flaw is reflected XSS, it can be triggered remotely by a malicious link or embedded content, meaning any user who visits a page rendered by the theme could be affected. The risk remains significant enough to warrant timely patching.

Generated by OpenCVE AI on April 30, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Electrician theme to the latest version that includes the XSS fix or a patched release.
  • If an immediate update is not possible, implement an application‑level output sanitization routine or disable the vulnerable input fields to prevent script injection.
  • Deploy a web‑application firewall rule that blocks reflected XSS payloads for the affected endpoints.

Generated by OpenCVE AI on April 30, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21612 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress allows Reflected XSS. This issue affects Electrician - Electrical Service WordPress: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress allows Reflected XSS. This issue affects Electrician - Electrical Service WordPress: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress electrician allows Reflected XSS.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00032}


Wed, 16 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vergatheme Electrician - Electrical Service WordPress allows Reflected XSS. This issue affects Electrician - Electrical Service WordPress: from n/a through 1.0.
Title WordPress Electrician - Electrical Service WordPress theme <= 1.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:30:23.184Z

Reserved: 2025-03-26T09:23:42.945Z

Link: CVE-2025-31055

cve-icon Vulnrichment

Updated: 2025-07-16T16:21:24.328Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T12:15:25.583

Modified: 2026-04-23T15:27:37.330

Link: CVE-2025-31055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T16:45:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')