Impact
The WoodMart theme contains an improper neutralization of user input that allows a DOM‑based XSS flaw. A malicious actor can inject arbitrary scripts into pages rendered with the theme, potentially executing code with the victim’s permissions. This can lead to theft of credentials, session hijacking, or other client‑side attacks.
Affected Systems
The vulnerability exists in the WoodMart theme from XTemos in all released versions up to, but not including, 8.3.2. Any WordPress site that has installed an affected WoodMart theme is susceptible.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation would typically require an attacker to supply crafted input that the theme renders without proper sanitization, often in the form of a link or page view a victim needs to open; based on the description, it is inferred that the likely attack vector is User‑Agent / Web page rendering.
OpenCVE Enrichment