Impact
Improper Neutralization of Input During Web Page Generation leads to Cross‑Site Scripting in the WordPress Togo theme. The vulnerability allows an attacker to inject scripts that are rendered in a visitor’s browser, potentially enabling session hijacking, defacement, or the delivery of malware. The flaw resides in how the theme processes untrusted input before rendering.
Affected Systems
The affected product is the Togo theme from the vendor uxper. Versions from the initial release up to any release older than version 1.0.4 are impacted by this issue. No later version has been reported as vulnerable.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity, but its EPSS of less than 1% indicates a very low likelihood of exploitation as of the current data. The theme is not listed in the CISA KEV catalog, meaning no widespread, confirmed exploit is known yet. Attackers would most likely target users who view pages generated by the vulnerable theme, or inject malicious content via administrative input that the theme does not properly sanitize.
OpenCVE Enrichment