Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw that allows an attacker to embed malicious scripts into the rendered page. An attacker who can control the input can cause arbitrary browser‐side code execution for users who view the crafted page, leading to session hijacking, data theft, or defacement. The weakness is identified as CWE‑79.
Affected Systems
The affected product is the Druco WordPress theme published by skygroup. Versions up to and including 1.5.2 are vulnerable; any release newer than 1.5.2 is not impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity. The EPSS score of less than 1 % suggests that the likelihood of real-world exploitation is low at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via a crafted URL or form submission that an unsuspecting user will open or submit, which triggers a reflected script injection. No additional environmental prerequisites are noted, so the flaw can be exploited by any external attacker that can direct a victim to a vulnerable page.
OpenCVE Enrichment
EUVD