Impact
An unauthenticated cross‑site scripting flaw exists in the Artale – Wedding Photography WordPress theme up to version 2.2.2. It enables an attacker to inject arbitrary JavaScript into content that the theme outputs to visitors, which can result in cookie theft, session hijacking, defacement, or redirecting users to malicious sites. The exploit relies on user‑controlled input that the theme renders, such as comments, reviews, or contact‑form submissions.
Affected Systems
All installations of the ThemeGoods Artale – Wedding Photography WordPress theme that are version 2.2.2 or earlier are vulnerable. Sites using these releases should verify the theme version and apply the latest update.
Risk and Exploitability
The CVSS score of 7.1 classifies this vulnerability as high severity. An EPSS score of < 1% indicates a low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote and unauthenticated, requiring an attacker to embed malicious scripts in content that the theme later outputs. Successful exploitation would run in the visitor’s browser and could compromise sessions, deface content, or facilitate phishing.
OpenCVE Enrichment