Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, or DOM-Based XSS, in the WordPress Select Core plugin. It enables an attacker to inject malicious JavaScript that is executed in the victim’s browser, allowing cookie theft, session hijacking, or malicious site defacement, thereby compromising confidentiality, integrity, and potentially the integrity of the web application.
Affected Systems
The Select-Themes Select Core WordPress plugin is affected for all releases from its initial version through any version prior to 2.6. Any WordPress site running a pre‑2.6 version of this plugin is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote via HTTP(S) access to the site, as an attacker only needs to deliver crafted input that the plugin processes during page generation.
OpenCVE Enrichment