Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes xSmart xsmart allows Reflected XSS.This issue affects xSmart: from n/a through <= 1.2.9.4.
Published: 2026-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation in the xSmart theme. A malicious user can supply crafted query parameters or form data that is not properly sanitized and is echoed back into the browser, leading to a reflected XSS. An attacker who succeeds can execute arbitrary JavaScript in the context of the victim's browser, allowing session hijacking, phishing, or defacement. The weakness is a classic input validation flaw identified as CWE‑79. The impact is limited to the context of the web page rendered by the affected theme and can compromise confidentiality, integrity, and availability of the affected site if the user interacts with the crafted content.

Affected Systems

The xSmart WordPress theme version 1.2.9.4 and all earlier releases published by Jthemes are vulnerable. Any WordPress installation that includes these theme files is at risk.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity. The EPSS score is less than 1 %, suggesting that, while the vulnerability exists, the projected exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. Exploits require an attacker to convince a victim to visit a crafted URL or submit a malicious form to a site running the affected theme. No authentication is needed, and the exploitation can be performed over the public internet. Due to the reflected nature, the attack surface is relatively large but may be mitigated by user behaviour and browser security controls.

Generated by OpenCVE AI on April 30, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the xSmart theme to a version newer than 1.2.9.4, if a newer version is available.
  • If an upgrade is not immediately possible, restrict the theme’s sensitive input fields to only allow alphanumeric characters or apply a content‑filtering plugin that sanitizes all output.
  • Deploy a Web Application Firewall that blocks or sanitizes reflected XSS payloads before they reach the browser.
  • Configure browsers to enable built‑in XSS protection and display https warnings for the site.

Generated by OpenCVE AI on April 30, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes xSmart xsmart allows Reflected XSS.This issue affects xSmart: from n/a through <= 1.2.9.4.
Title WordPress xSmart theme <= 1.2.9.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:15.890Z

Reserved: 2025-06-11T16:08:11.572Z

Link: CVE-2025-50006

cve-icon Vulnrichment

Updated: 2026-01-26T21:58:46.283Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:57.140

Modified: 2026-04-27T16:16:27.973

Link: CVE-2025-50006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:30:27Z

Weaknesses