Impact
This issue arises from improper neutralization of user input in the ThemeREX Addons addon, allowing attackers to store malicious JavaScript within the plugin’s static content or form fields. The vulnerability permits a stored XSS attack, which can execute arbitrary scripts in the browsers of users who view the affected content, potentially leading to credential theft, session hijacking, or defacement of the website. The weakness is a classic CWE-79, and the impact is confined to users who can view the compromised pages, not to the server itself or data confidentiality. The CVSS score of 6.5 reflects a medium‑to‑high severity for web applications where client‑side code injection can compromise user sessions.
Affected Systems
The affected product is the WordPress ThemeREX Addons plugin delivered by ThemeREX Group. All releases from the earliest available version up through 2.46.0 are vulnerable. The vulnerability would affect any WordPress site that has this plugin installed and is using any of those versions, regardless of site configuration or theme.
Risk and Exploitability
The vulnerability carries a CVSS of 6.5 and is not listed in CISA’s KEV catalog. No EPSS score is available, so the current exploitation probability is unknown but potentially modest. Attackers would likely exploit the plug‑in’s form or content storage mechanisms using a browser with sufficient privileges; the stored payload would persist in the database and execute every time affected content is rendered. Because the impact is limited to the victim’s browser session, credential hijacking or site defacement are realistic possible outcomes. In the absence of a patch, the risk remains medium‑to‑high for any site that has active users who browse dynamically rendered content from the plugin.
OpenCVE Enrichment