Impact
An unauthenticated Cross Site Scripting vulnerability exists in the Word7 allows arbitrary into web pages viewed by site visitors. Based on the description, it is inferred that user input may not be properly sanitized, giving an attacker the ability to execute JavaScript when the page is rendered.
Affected Systems
All releases of DesignThemes' Trendy Travel WordPress theme through version 6.7 are affected. Site owners who have not upgraded beyond 6.7 are at risk.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity, but the EPSS score of <1% indicates a very low current likelihood. The attack vector is remote, via crafted URLs or form inputs that cause the browser to render untrusted data, allowing the execution of malicious JavaScript in the context of site visitors.
OpenCVE Enrichment