Impact
The vulnerability arises from improper neutralization of user input during web page generation, enabling DOM‑Based XSS. Attackers can inject malicious scripts that run in the browser of visitors, potentially leading to defacement, phishing, or session hijacking. The flaw is identified as CWE‑79.
Affected Systems
The issue affects GT3themes’ Oyster – Photography WordPress Theme for all versions up to and including 4.4.3. Users running any of these releases are at risk.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is moderate to high. The EPSS score is below 1%, indicating low probability of widespread exploitation, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, typically via a visitor interacting with the site or submitting content through the theme’s front‑end functionality.
OpenCVE Enrichment