Impact
The flaw is an unauthenticated cross‑site scripting (XSS) vulnerability in the Artale WordPress theme, affecting all versions 2.2.2 and earlier. It allows an attacker to inject arbitrary script code into the context of site visitors. The CVE description does not specify exact consequences, but cross‑site scripting can enable actions such as stealing session cookies, defacing content, or redirecting users to malicious sites – these consequences are inferred from the nature of XSS.
Affected Systems
This issue affects all installations of the ThemeGoods Artale – Wedding Photography WordPress theme that are version 2.2.2 or earlier. Administrators should verify whether they are running a vulnerable version.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a very low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of widespread exploitation yet. The attack vector is likely remote and unauthenticated, requiring an attacker to embed malicious code in content that the theme renders, such as comments or other user‑controlled input. Based on the description, it is inferred that exploitation would allow a remote attacker to inject arbitrary script, potentially leading to cookie theft, session hijacking, defacement, or phishing redirection.
OpenCVE Enrichment