Impact
This vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of user input during page generation. An attacker can inject malicious JavaScript that will run in the victim’s browser whenever a compromised page is rendered, enabling session hijacking, defacement, or other client‑side attacks.
Affected Systems
All installations of the Enfold WordPress theme supplied by Kriesi with a version of 7.1.3 or earlier are affected. No additional sub‑version information is provided, so every release through 7.1.3 is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 places this issue in the medium severity range. The EPSS score of less than 1% suggests that exploitation is unlikely at the moment, and it is not listed in the CISA KEV catalog. The attack vector is most likely user‑controlled input such as query parameters or theme‑option values that are reflected into the DOM without proper sanitization, and exploitation requires the victim to load a page with a crafted payload.
OpenCVE Enrichment