Impact
The Photography theme includes a reflected XSS flaw where untrusted input is not properly escaped before being rendered. As a result, an attacker can inject malicious script into the page, potentially compromising user credentials, defacing the site, or redirecting visitors, as indicated by the CWE‑79 classification. This vulnerability does not grant arbitrary code execution, but it can be used for credential theft or malicious advertising when users load the page.
Affected Systems
ThemeGoods Photography theme versions up to and including 7.7.2 are affected. Publicly available releases prior to 7.7.3 inherit the flaw; any instance of the theme running those legacy versions is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects a high impact scenario that depends on the ability of an attacker to craft a URL or form value. The EPSS score of less than 1% suggests that exploitation is not currently widespread, and the vulnerability is not listed in CISA KEV, so no confirmed exploits are known. Nevertheless, because reflected XSS can lead to session hijacking or defacement, the risk is non‑negligible, especially on active sites that allow user input. Based on the description, it is inferred that the attack vector is web‑based through crafted query parameters or form submissions.
OpenCVE Enrichment