Impact
The CVE exposes an improper neutralization of input during page generation in the kamleshyadav RockON DJ theme, enabling attackers to inject arbitrary JavaScript through reflected Cross‑Site Scripting into pages rendered by the theme.
Affected Systems
All WordPress installations using the kamleshyadav RockON DJ theme up to and including version 3.3 are affected; earlier or newer versions are not impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity, while the EPSS score of <1% suggests a low probability of widespread exploitation. Because it is a reflected XSS, an attacker must lure a user to click a crafted link or load a malicious URL; the flaw does not give the attacker direct code execution on the server but can compromise the victim’s browser. The flaw is not listed in CISA KEV, and no vendor patch is currently available.
OpenCVE Enrichment