Impact
The vulnerability stems from improper input neutralization during page rendering, leading to reflected cross‑site scripting. An attacker who can craft a URL or user‑input containing malicious JavaScript can have that code executed in the victim’s browser. This can be leveraged for phishing, credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79.
Affected Systems
The issue affects the WordPress Elessi theme produced by NasaTheme. All releases up to and including version 6.3.9 are vulnerable; versions beyond 6.3.9 are presumed patched. No other vendors or products are listed.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation out of the box, and the vulnerability is not yet listed in CISA’s KEV catalog. Because the flaw is reflected, the attacker must be able to entice a user to visit a crafted link or submit crafted data. No local‑privilege escalation is required; the attack can be carried out remotely from any network with internet access.
OpenCVE Enrichment
EUVD