Impact
The vulnerability is an improper neutralization of user-supplied input during page rendering, allowing an attacker to inject malicious scripts that are reflected back to the victim’s browser. This Reflected XSS can be used to hijack sessions, deface content, or deliver phishing payloads when a user visits a crafted URL or submits data that is echoed in the page. The weakness is categorized as CWE‑79 and does not provide remote code execution but does compromise confidentiality and integrity of the user session.
Affected Systems
The defect affects the Sneeit MagOne theme for WordPress, versions from the earliest available through 8.8 inclusive. Any site that has installed MagOne theme v8.8 or lower is susceptible; newer releases beyond 8.8 have not been reported as vulnerable.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered high severity, yet the EPSS score of less than 1% indicates a low likelihood that it is currently being exploited in the wild. It is not listed in the CISA KEV catalog, further suggesting limited exploitation. The attack vector is reflected based on user-controllable parameters accessible via normal URLs or form submissions; the attacker needs the victim to click or input the malicious payload, but no privileged or local access is required.
OpenCVE Enrichment
EUVD