Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into a visitor’s browser when the SpaLab theme is used. The weakness is a classic input‑validation error identified as CWE‑79.
Affected Systems
The flaw affects installations of the Designthemes SpaLab Beauty Salon WordPress Theme with versions 6.7 and earlier. Any WordPress site deploying this theme without an upgrade is susceptible, regardless of the underlying WordPress core version.
Risk and Exploitability
The CVSS score for this vulnerability is 7.1. EPSS indicates a very low exploitation probability (< 1%). Based on the description, the likely attack vector is that an attacker can exploit the flaw simply by directing a user to site or crafting that leads a visitor to the vulnerable theme. Because the flaw is client‑side and does not require authentication, anyone visiting the site is at risk. The vulnerability is not listed in the CISA KEV catalog, which indicates no known widespread exploitation reports.
OpenCVE Enrichment