Impact
The LMS theme contains an Improper Neutralization of Input During Web Page Generation issue, classified as a Reflected Cross‑Site Scripting (XSS) vulnerability. The theme does not properly sanitize user input before rendering it, which means an attacker can supply specially crafted data that will be reflected into the page and executed as script within the victim’s browser. This enables malicious code to run in the user’s context, potentially undermining the integrity of the information the user accesses while interacting with the site.
Affected Systems
WordPress LMS theme provided by designthemes, affecting all releases from unversioned through 9.2 inclusive.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk. The EPSS score of <1% suggests low current exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is reflected XSS via crafted URLs or form inputs that the theme echoes back, requiring only a victim to be tricked into visiting a malicious link. Exploitation does not require authentication or administrative privileges; any user can trigger it through a crafted request.
OpenCVE Enrichment
EUVD