Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing an attacker to inject script code that will execute in the browsers of visitors who load a malicious URL. This reflected XSS flaw can lead to session hijacking, theft of credentials, and defacement of the site. It exploits the lack of proper input validation and escaping, as identified by CWE‑79.
Affected Systems
The Sala theme for WordPress, produced by uxper, is vulnerable in all releases up to and including version 1.1.3. Any instance deploying these versions is at risk, regardless of the WordPress core or PHP version.
Risk and Exploitability
The risk is moderate due to a CVSS score of 7.1, indicating that the flaw could have a significant impact on confidentiality, integrity, and availability if abused. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently low, and the vulnerability is not listed in CISA’s KEV catalog. However, the flaw can be triggered by simply visiting a crafted link or clicking a malicious email link, so attackers who target the site’s audience could exploit it.
OpenCVE Enrichment