Impact
The Bridge - Creative Multipurpose WordPress Theme for WordPress is vulnerable to Stored Cross‑Site Scripting via the 'circle_line' shortcode attribute. Insufficient input sanitization and output escaping allow authenticated users with contributor-level access or higher to inject arbitrary JavaScript that will execute on any user who views the affected page.
Affected Systems
The vulnerability affects the QODE Bridge Creative Multipurpose WordPress Theme version 30.8.9.1 and all earlier releases. Users running any of those versions are at risk.
Risk and Exploitability
The flaw is a CWE‑79 stored cross‑site scripting weakness. The medium severity. Because the vulnerability requires authenticated contributor‑level access, the attack vector is limited to authenticated users. The EPSS score is < 1%, indicating a very low probability of exploitation. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment