Impact
This vulnerability is a Reflected Cross‑Site Scripting flaw caused by improper sanitization of user input in the ThemeGoods Grand Spa WordPress theme. An attacker can embed malicious JavaScript into URLs that the theme processes without neutralizing, resulting in the code being executed in the browsers of unsuspecting visitors. The impact is the possible theft of session data, defacement of the website, and execution of arbitrary scripts with the privileges of the user who visits the malicious link. The weakness corresponds to CWE‑79.
Affected Systems
ThemeGoods Grand Spa theme versions up to and including 3.5.5 are affected. Any WordPress installation using this theme at those versions is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation would occur via a crafted URL that an attacker sends to a victim, exploiting the reflected XSS weakness. The vulnerability is exploitable by unauthenticated users viewing the impacted pages, making it a widespread threat in environments where the Grand Spa theme is deployed.
OpenCVE Enrichment