Impact
The vulnerability is an improper neutralization of input during web page generation that permits attackers to store malicious scripts within the Modernize theme. Stored XSS can lead to session hijacking, defacement, or redirection on the victim’s browser, impacting the confidentiality and integrity of user sessions.
Affected Systems
Affected are installations of the GoodLayers Modernize WordPress theme with versions up to 3.4.0, including all WordPress sites that currently use these or earlier releases of the theme.
Risk and Exploitability
The CVSS score of 6.5 signals moderate severity, while an EPSS score of <1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to submit data through the theme’s input fields to inject script, typically via the admin interface, after which the stored payload will be rendered for any site visitor.
OpenCVE Enrichment
EUVD