Impact
Improper neutralization of user‑supplied data during page rendering results in a DOM‑Based XSS flaw in the Soledad theme. An attacker who can influence elements of the page—such as by supplying crafted URLs, comments, or widget content—can inject malicious JavaScript that will run in the context of the site. This can lead to credential theft, defacement, or further compromise of the web application.
Affected Systems
WordPress sites using the Soledad theme version 8.6.8 or earlier from PenciDesign are affected. The issue applies across all builds from the earliest release up through 8.6.8.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS is under 1%, implying a low probability of widespread exploitation, and the issue is not currently listed in the CISA KEV catalog. Attackers would need to attract unsuspecting visitors to the target site, typically via phishing or social engineering, to trigger the DOM analysis and execute their payload.
OpenCVE Enrichment
EUVD