Impact
Unauthenticated Cross Site Scripting vulnerability in WordPress Fitness Zone Theme versions 5.7 and earlier permits an attacker to inject arbitrary JavaScript into web pages rendered by the site visitor. This is inferred because the vulnerability is unauthenticated and does not require any user privilege to exploit. This flaw qualifies as a classic XSS weakness (CWE‑79) because it involves placing malicious code into the page output without proper sanitization.
Affected Systems
Any WordPress site that is running the Designthemes Fitness Zone WordPress Theme at version 5.7 or older is affected, regardless of the WordPress core version or additional plugins in use.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity; the EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because no user authentication is required, it is inferred that any visitor who loads a page served by the vulnerable theme could be exposed to injected scripts.
OpenCVE Enrichment