Impact
Improper neutralization of input during web page generation allows stored XSS. The vulnerability resides in the Seven Stars theme’s handling of user‑supplied data, enabling an attacker to embed malicious scripts that are saved and served to site visitors. The consequence is that any user who loads a page containing the injected payload could have their session hijacked, cookies stolen, or arbitrary code executed in their browser. This meeting the criteria of CWE‑79.
Affected Systems
The Seven Stars WordPress theme by themeton, versions up to and including 1.4.4, are affected. All releases preceding 1.4.5 contain the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity. The EPSS score of less than 1% suggests low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to inject malicious content, typically through an admin or plugin interface that accepts unchecked input. Once stored, any authenticated or unauthenticated site visitor can trigger execution when the page loads. Attackers therefore need administrative privileges or the ability to inject content, but the payload can reach a wide audience without their knowledge.
OpenCVE Enrichment
EUVD