Impact
The Hoteller theme does not properly neutralize input before rendering it, which lets an attacker inject malicious scripts that execute in the context of the victim's browser. Because the payload is reflected back in the page, a malicious URL or form submission can cause arbitrary JavaScript to run, enabling credential theft, defacement or redirect of the user. The weakness aligns with CWE‑79.
Affected Systems
All WordPress sites using ThemeGoods Hoteller theme versions earlier than 6.8.9 are vulnerable, including installations that lack a formal release number (n/a). Upgrading to 6.8.9 or later resolves the issue.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score below 1 % suggests a low probability of being actively exploited at present, and the vulnerability is not listed in the CISA KEV catalog. However, because reflected XSS relies on user interaction, an attacker still needs a poisoned URL or form to trick a victim. The attack is typically local to a user’s session and does not require privileged access to the server.
OpenCVE Enrichment