Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi elessi-theme allows Reflected XSS.This issue affects Elessi: from n/a through <= 6.3.9.
Published: 2025-06-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from improper input neutralization during page rendering, leading to reflected cross‑site scripting. An attacker who can craft a URL or user‑input containing malicious JavaScript can have that code executed in the victim’s browser. This can be leveraged for phishing, credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79.

Affected Systems

The issue affects the WordPress Elessi theme produced by NasaTheme. All releases up to and including version 6.3.9 are vulnerable; versions beyond 6.3.9 are presumed patched. No other vendors or products are listed.

Risk and Exploitability

The CVSS base score is 7.1, indicating high severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation out of the box, and the vulnerability is not yet listed in CISA’s KEV catalog. Because the flaw is reflected, the attacker must be able to entice a user to visit a crafted link or submit crafted data. No local‑privilege escalation is required; the attack can be carried out remotely from any network with internet access.

Generated by OpenCVE AI on April 30, 2026 at 10:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Elessi theme to the latest released version (6.4 or newer) which removes the unsanitized output.
  • Implement a strict Content Security Policy to restrict JavaScript execution to trusted sources.
  • Apply input validation or sanitization on any custom fields or URL parameters that the theme echoes.
  • If an update is not immediately possible, consider disabling the theme’s dynamic parameters or use a web application firewall rule to block malicious scripts.

Generated by OpenCVE AI on April 30, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28328 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi allows Reflected XSS. This issue affects Elessi: from n/a through 6.3.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi allows Reflected XSS. This issue affects Elessi: from n/a through 6.3.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi elessi-theme allows Reflected XSS.This issue affects Elessi: from n/a through <= 6.3.9.
Title WordPress Elessi <= 6.3.9 - Cross Site Scripting (XSS) Vulnerability WordPress Elessi theme <= 6.3.9 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi allows Reflected XSS. This issue affects Elessi: from n/a through 6.3.9.
Title WordPress Elessi <= 6.3.9 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:06.738Z

Reserved: 2025-06-11T16:06:05.695Z

Link: CVE-2025-49873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:20.990

Modified: 2026-04-23T15:31:45.610

Link: CVE-2025-49873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:45:26Z

Weaknesses