Impact
The vulnerability is a reflected XSS flaw caused by improper neutralization of input during web page generation in the Kalium theme. Attackers can inject arbitrary scripts that will run in the browsers of users who view affected pages, potentially leading to session hijacking, defacement or unauthorized actions. This weakness is identified as CWE‑79.
Affected Systems
All installations of the Laborator Kalium WordPress theme with versions up to and including 3.18.3 are affected. The flaw applies to every release of the theme from its earliest versions through 3.18.3. Any WordPress site that uses the Kalium theme without upgrading beyond 3.18.3 may be exploitable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity issue. The EPSS score is below 1 %, suggesting a low probability of exploitation in the near term, and the flaw is not listed in the CISA KEV catalog. Because the vulnerability is reflected, it can be triggered by any user who sends a crafted request to a vulnerable page, so the attack vector is remote and does not require privileged access.
OpenCVE Enrichment