Impact
Improper neutralization of input during web page generation allows a reflected cross‑site scripting flaw in the Frenify Arlo WordPress theme. An attacker can embed malicious script code in the page that is executed in a victim’s browser, enabling client‑side code execution. The weakness is a classic input validation issue (CWE‑79).
Affected Systems
WordPress sites using the Frenify Arlo theme version 6.0.3 or earlier are affected. The vulnerability spans all revisions of the theme from its earliest releases up to and including 6.0.3.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning there are no publicly known exploits. Based on the description, the likely attack vector is a crafted URL or form input that the theme does not properly sanitize, allowing an attacker to inject JavaScript that the victim's browser executes.
OpenCVE Enrichment