Impact
This vulnerability arises from improper neutralization of input during web page generation in the G5Theme Zorka theme, allowing a reflected Cross‑Site Scripting (XSS) attack. The flaw permits an attacker to inject malicious scripts that are reflected back in the browser response, enabling client‑side code execution when a victim follows a crafted link.
Affected Systems
WordPress installations that use the G5Theme Zorka theme version 1.5.7 or earlier are vulnerable. Any site that has not upgraded past this version is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, and while the EPSS score is not available, the lack of KEV listing suggests this is not yet widely exploited. The likely attack vector is an attacker-created URL containing malicious input that is reflected in the page. Successful exploitation can lead to theft of session cookies, unauthorized account access, or the delivery of additional malware to unsuspecting users. System‑wide impact depends on the privileges of the affected user and the scope of the site’s content. The vulnerability is exploitable by anyone who can cause a victim to request a maliciously crafted URL, making it broadly feasible.
OpenCVE Enrichment