Impact
The vulnerability exists in the WordPress HYDRO theme, allowing an attacker to inject malicious JavaScript through unneutralized user input that is displayed back to users. This reflected XSS can be used to steal session cookies, deface content, or deliver further malware, compromising the confidentiality and integrity of visitors and potentially the site's reputation.
Affected Systems
All WordPress installations using BuddhaThemes HYDRO theme version 2.8 or earlier are susceptible. The impact is limited to sites that have the theme active and are accessible to the public.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑risk vulnerability; however the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires a user to visit a crafted URL that takes advantage of the theme's reflected input. The attack vector is remote, and success depends on the website rendering unescaped user data.
OpenCVE Enrichment
EUVD