Impact
The WoodMart theme for WordPress contains a stored cross‑site scripting flaw in its plugin’s multiple_markers attribute. Insufficient input sanitization allows an authenticated user with contributor access or higher to embed arbitrary JavaScript. When a victim opens the injected page, the script runs in the victim’s browser, enabling session hijacking, defacement, or data theft.
Affected Systems
The vulnerability affects the Woodmart WordPress theme supplied by xTemos. All releases up to and including version 8.2.3 are vulnerable. Users or sites that have granted contributor-level or higher permissions to attackers can exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of real‑world exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the flaw is limited to authenticated contributors, so an insider threat or compromised account would be needed. Once injected, the script executes on all browsers that load the affected page, leading to potential data theft or session hijacking.
OpenCVE Enrichment
EUVD