Impact
Improper neutralization of user input during web page generation allows a reflected XSS flaw to be exercised in the designthemes Ofiz – WordPress Business Consulting Theme. The flaw permits an attacker to embed arbitrary JavaScript via encoded parameters, which is then executed in the victim’s browser. This can lead to credential theft, defacement, or the execution of further malicious actions within the scoped audience of the infected site.
Affected Systems
The WordPress Business Consulting Theme by designthemes, any installation using version 2.0 or earlier. No explicit patch version is listed, so any theme instance under <= 2.0 remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% suggests the likelihood of exploitation is low at this time. The vulnerability is not included in the CISA KEV catalog, yet attackers could still leverage the reflected XSS via crafted URLs on publicly accessible pages. The attack vector is likely through a publicly reachable input field that the theme fails to sanitize.
OpenCVE Enrichment
EUVD