Impact
The WordPress TheNa theme (versions up to 1.5.5) contains an improper neutralization of input during web page generation that allows reflected cross‑site scripting. Attackers can inject malicious JavaScript through a crafted URL that is reflected back into the page output, leading to execution of arbitrary code in the victim’s browser. This may enable session hijacking, defacement, or credential theft.
Affected Systems
The vulnerability affects the TheNa theme from foreverpinetree for WordPress. All builds of the theme released through version 1.5.5 are impacted. Any WordPress site that still uses a version 1.5.5 or earlier is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of reflected XSS, the likely attack vector is a remote web‑based one that requires a user to visit a crafted link; the attacker must entice the victim into clicking the malicious URL.
OpenCVE Enrichment