Impact
The vulnerability is an improper neutralization of script-related HTML tags, allowing basic XSS or injection of arbitrary code in the context of the site’s users. If an attacker can insert malicious script, they may hijack sessions, deface the site, or execute further attacks from the victim’s browser.
Affected Systems
Jthemes’ xSmart WordPress theme is affected in all releases through version 1.2.9.4. No specific minimum version is listed, indicating the issue exists in all older or earlier releases of the theme.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% signals a very small chance of exploitation. The vulnerability is not included in the CISA KEV catalog, suggesting no known public exploits. The likely attack vector is via the theme’s content administration interface, where an authenticated or potentially unauthenticated user could inject HTML that browsers will execute.
OpenCVE Enrichment