Impact
The vulnerability is an improper neutralization of user input during web page generation that permits reflected cross‑site scripting. An attacker can embed malicious script content in user‑controlled fields; when a victim’s browser renders the affected page, the script executes in the browser context. The issue is classified as CWE‑79.
Affected Systems
The issue affects the skygroup UpStore theme for WordPress across all versions from the first release up to and including 1.7.0. Any website that still uses an affected version is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS score is less than 1 %, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in CISA KEV. Exploitation can be performed by providing a crafted URL or content that includes malicious script, which will be reflected in the rendered page.
OpenCVE Enrichment
EUVD