Impact
The vulnerability allows an authenticated contributor or higher to inject arbitrary JavaScript into pages via the lightbox rendering code in The7 theme. Unsanitized title and data‑dt‑img‑description attributes are read, concatenated into an HTML string, and inserted into the DOM. An attacker can therefore execute scripts in the browser of any user who views the affected page, enabling credential theft, session hijacking, and defacement.
Affected Systems
Dream Theme The7 – WordPress theme, all releases up to and including 12.6.0 are affected. The vulnerability is present in every installation using the impacted versions of the theme.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability, and the EPSS score of less than 1% shows a low likelihood of exploitation at this time. The vulnerability is not listed in CISA KEV. Attack requires authenticated access with contributor or higher privileges; the entry point is the image lightbox where title attributes are processed without escaping.
OpenCVE Enrichment
EUVD