Impact
Improper neutralization of user input during web page generation allows injected scripts to be reflected back to the victim. The flaw enables client‑side code execution, allowing an attacker to run arbitrary JavaScript while a user visits a page rendered by the vulnerable WordPress Uncode theme.
Affected Systems
The vulnerability exists in the WordPress Uncode theme supplied by undsgn. All releases prior to version 2.9.4.4 are affected; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% shows a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. According to the description, the likely attack vector is a malicious URL or form that a site visitor opens or submits, which causes the reflected script to execute in the victim’s browser. No privileged access or server compromise is required.
OpenCVE Enrichment
EUVD