Impact
This vulnerability is an improper neutralization of user input during web page generation in the Rocket Apps wProject theme, allowing an attacker to insert arbitrary HTML or script into a page. When a victim loads a crafted URL or is tricked into clicking a malicious link, the injected code is executed in the victim’s browser, potentially enabling session hijacking, phishing, or defacement. The impact is to compromise the confidentiality and integrity of the user’s session and data on the affected WordPress site.
Affected Systems
The wProject theme by Rocket Apps, any version older than 5.8.0, is affected. No other products or versions are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw, but the EPSS score is less than 1% and the vulnerability is not in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation at present. The attack vector is a typical web‑application scenario; an attacker must craft a URL or form input that the theme fails to sanitize, causing the server to echo the payload back in the browser. Any authenticated or unauthenticated user who visits the affected page can become a victim.
OpenCVE Enrichment
EUVD