Impact
Improper Neutralization of Input During Web Page Generation allows attackers to inject malicious scripts into pages served by WordPress sites that use the ApusTheme Butcher theme. This is a reflected XSS (CWE‑79) that can enable an attacker to execute arbitrary JavaScript in the context of unsuspecting users, potentially leading to session hijacking, credential theft, or content defacement.
Affected Systems
All WordPress installations that have the ApusTheme Butcher theme at a version earlier than 2.54 are affected. The advisory does not specify exact version numbers prior to 2.54, so any install of the theme below this threshold is considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through crafted URLs or user‑input fields that the theme reflects back to the browser. Because the exploit is client‑side, it can be performed by unauthenticated users who can influence the victim’s browser.
OpenCVE Enrichment
EUVD