Impact
The Rehub theme contains an improper neutralization of input that allows attackers to store malicious JavaScript in the web page content. This stored cross‑site scripting can execute arbitrary code in the context of any visitor, enabling cookie theft, session hijacking, phishing or site defacement. The weakness is categorized as CWE‑79.
Affected Systems
All installations of the sizam Rehub theme with a version lower than 19.9.9.1 are impacted. No specific minor versions are listed; the vulnerability is present throughout the entire range from the first release up to just before 19.9.9.1.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of <1% suggests a low probability of active exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by injecting crafted scripts into any input field handled by the theme, which are then stored in the database and re‑rendered to site visitors. Successful exploitation requires the victim to view the affected page, where the malicious payload executes in the victim’s browser.
OpenCVE Enrichment