Impact
The vulnerability arises from inadequate input sanitization in the ThemeGoods Craft WordPress theme, allowing an attacker to embed malicious JavaScript in a web page that is reflected back to the user. This DOM‑based XSS can be used to hijack user sessions, deface content, or steal credentials when victims interact with the affected page. The flaw is a typical injection weakness (CWE‑79) that affects the presentation layer of the theme.
Affected Systems
The affected product is the WordPress theme Craft by ThemeGoods, versions 2.3.6 and earlier. Site owners using this theme in any WordPress installation are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for potential attackers. The EPSS score is below 1 %, suggesting that exploitation attempts are currently rare, but the flaw remains exploitable through reflected inputs such as query parameters or form submissions. The issue is not yet listed in the CISA KEV catalog, so there is no evidence of widespread exploitation. However, the typical attack path requires a victim to click a crafted URL or submit malicious input, after which the browser executes the injected code.
OpenCVE Enrichment