Impact
Improper neutralization of input in the Theme Switcha plugin allows stored XSS on WordPress sites. The flaw lets an attacker inject malicious script that is permanently rendered when a visitor loads the page. Because the payload is stored server‑side, it can affect all users of the site and lead to cookie theft, defacement or execution of arbitrary client‑side code.
Affected Systems
The vulnerability is present in Theme Switcha version 3.4 and earlier from the developer Jeff Starr. WordPress installations that use this plugin without updating to a newer release are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% shows a very low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers would typically create a malicious input through the plugin’s configuration or content entry interfaces, which the plugin then stores and later outputs to visitors without proper escaping.
OpenCVE Enrichment
EUVD