Impact
The CVE details an improper neutralization of input during web page generation in the PhotoMe theme. The theme fails to escape user‑controlled data, permitting a DOM‑based cross‑site scripting payload to execute when the page loads. An attacker can inject arbitrary JavaScript that runs in the browser of any visitor, enabling cookie theft, session hijacking, defacement, or redirection.
Affected Systems
Affected are all installations of ThemeGoods PhotoMe for WordPress with version numbers up to and including 5.7.1. The vulnerability does not affect later releases; upgrading beyond 5.7.1 no longer contains the flaw.
Risk and Exploitability
The CVSS base score of 7.1 reflects a moderate severity. The EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely triggered by a victim clicking a crafted link or visiting a malicious page that contains the unescaped data. If exploited, the attacker can execute scripts in the victim's browser context, potentially compromising session credentials or delivering further malware.
OpenCVE Enrichment