Impact
The fitness‑park theme contains a DOM‑based cross‑site scripting flaw caused by improper neutralization of user input during web page generation. When a victim loads a page that includes or reflects unsanitized user data, the browser can execute arbitrary JavaScript supplied by an attacker, potentially allowing the attacker to run code with the victim’s browser context.
Affected Systems
All WordPress sites that have installed the sparklewpthemes Fitness Park theme version 1.1.1 or earlier are vulnerable. The flaw is confined to the theme’s client‑side JavaScript and does not affect the underlying WordPress installation or server‑side code.
Risk and Exploitability
The CVSS score indicates a medium severity vulnerability, and the EPSS score of less than 1 % suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a user visiting a URL or loading a page that contains malicious input designed to trigger the DOM‑based XSS; exploitation requires user interaction and can be facilitated through social engineering or deceptive links.
OpenCVE Enrichment
EUVD