Impact
The flaw is an instance of Improper Neutralization of Input During Web Page Generation, allowing an attacker to inject malicious script into a WordPress site that uses the KALLYAS theme. When the theme processes input or a crafted URL, the injected code is executed in the victim’s browser, enabling the attacker to steal session cookies, deface content, or deliver malware. Based on the description, the likely attack vector is inferred to be client‑side; the malicious code is run in the user’s browser and does not directly compromise server configuration or data integrity, but it can undermine user confidentiality and the integrity of displayed content.
Affected Systems
The vulnerability is present in all releases of the KALLYAS theme from hogash with a version less than 4.25.0. Any WordPress installation that has the theme activated and accepts user‑supplied input or manipulated URLs is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. The EPSS score of <1% shows that exploitation attempts are rare, and the issue is not listed in the CISA KEV catalog. Attack requires the victim to view a specially crafted page or submit malicious input, making it a remote but user‑interaction dependent threat. While the likelihood is low, the impact to affected users is significant if not mitigated.
OpenCVE Enrichment