Impact
An unauthenticated Cross Site Scripting vulnerability exists in the Kids Zone – Children WordPress Theme versions up to 5.4. The flaw allows an attacker to inject and execute arbitrary JavaScript when a page that uses the vulnerable theme is rendered. Because the code runs in the context of any site visitor, it can manipulate the page, steal data from the browser, or perform other malicious actions within that browser session.
Affected Systems
The theme version 5.4 and earlier from the Design Themes publisher. Any WordPress installation that has applied the Kids Zone – Children WordPress Theme with those versions is affected.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score of <1% indicates that unauthenticated, allowing any visitor to trigger the XSS if they can access a page that uses the theme. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment