Impact
The vulnerability arises from improper input neutralization in the Ronneby Theme Core plugin, resulting in DOM‑based XSS. An attacker can inject malicious scripts into a victim’s browser, potentially stealing session cookies, defacing content, or redirecting users. This flaw corresponds to CWE‑79 and allows attackers to tamper with the web page without requiring authentication.
Affected Systems
WordPress sites using the DFDevelopment Ronneby Theme Core plugin version 1.5.68 or earlier are affected. No other versions or products are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests low current exploitation probability, and the issue is not listed in the CISA KEV catalog. Attacks would most likely occur via a crafted URL that a user clicks, leading to script execution in the victim’s browser. The vulnerability is remote and does not require elevated privileges but can be used to hijack user sessions or perform phishing.
OpenCVE Enrichment