Impact
Improper neutralization of input during web page generation in the Minamaze theme allows stored cross‑site scripting. A malicious actor can embed script code that is persisted to the database and executed when other users view affected pages, potentially compromising user accounts or defacing the site.
Affected Systems
Any WordPress installation using the Minamaze theme up to version 1.10.1 is affected.
Risk and Exploitability
The vulnerability scores a CVSS of 6.5, indicating moderate severity, and has an EPSS score of less than 1 %, suggesting a low likelihood of exploitation in the wild. It is not listed in CISA KEV. The attack vector is most likely through any input point that stores user‑generated content, such as post editors or comment sections, where the malicious script can be injected and subsequently served to other visitors. Because the flaw is stored, an attacker can create a persistent payload that continuously compromises users until remediation is applied.
OpenCVE Enrichment