Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, resulting in a Reflected Cross‑Site Scripting flaw in the Easy Theme Options plugin. An attacker can embed malicious scripts in a crafted URL that the plugin does not sanitize. If a victim clicks the URL, the embedded script runs in the victim’s browser, allowing session hijacking, defacement, data theft, or redirection to malicious sites. The weakness maps to CWE‑79 and can affect the confidentiality, integrity, and availability of the user’s experience only while they interact with the vulnerable page.
Affected Systems
The issue affects WordPress Easy Theme Options plugin versions up to and including 1.0, as supplied by Remi Corson. Any WordPress site using this version of the plugin is susceptible.
Risk and Exploitability
The base CVSS score of 7.1 denotes high severity. The EPSS score of less than 1% implies a low but non‑zero likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. Recommended attack path involves an attacker crafting a malicious URL that the plugin processes and luring a user to visit it; upon visit, the reflected script executes in the user’s browser. No privileged access or remote code execution is required—determined solely by the user’s interaction with the crafted link.
OpenCVE Enrichment