Impact
The YOOtheme Pro WordPress theme versions prior to 5.0.35 allow authors to embed malicious JavaScript into post content. The bundled front‑end framework incorrectly treats certain HTML attributes as markup, enabling injected scripts to be stored and executed in the browsers of any visitor to the affected post. This stored cross‑site scripting can lead to theft of session cookies, account hijacking, or arbitrary client‑side code execution.
Affected Systems
All WordPress sites using YOOtheme Pro older than 5.0.35 with an Author role are vulnerable. An author can place a payload, and any other site visitor may be impacted when viewing the compromised post.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires author‑level privileges to insert content; the attack vector is stored XSS via injection of malicious UIkit data attributes into post content, inferred from the description. An attacker could use the stored script to steal cookies, hijack accounts, or execute arbitrary client‑side code against site visitors.
OpenCVE Enrichment