Impact
Improper neutralization of input during page generation in the shinetheme Traveler theme creates a reflected cross‑site scripting vulnerability. An attacker can embed malicious scripts into otherwise benign input fields or URLs, causing those scripts to execute in the context of a victim’s browser when the page is rendered. This can lead to session hijacking, credential theft, site defacement, or forced traffic redirection for unsuspecting users.
Affected Systems
The flaw exists in all releases of the Traveler WordPress theme prior to version 3.2.6. Whenever the theme is installed and active on a WordPress site, potential users are exposed to the XSS risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while the EPSS score of less than 1% suggests a very low chance of current exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by an unauthenticated attacker who can craft a malicious URL or form submission; the attacker does not need elevated privileges. The most likely attack surface is the theme’s public pages where user-supplied data is echoed without proper encoding.
OpenCVE Enrichment