Impact
Improper neutralization of user input during web page generation results in a DOM‑based XSS flaw, a CWE‑79 vulnerability, in the 8theme XStore theme, permitting an attacker to inject and execute arbitrary JavaScript code in the victim’s browser, potentially leading to session hijacking, defacement, or other client‑side abuses. Based on the description, these consequences are possible but not guaranteed by the CVE entry.
Affected Systems
WordPress sites that use the 8theme XStore theme version 9.6.4 or earlier are affected, as the vulnerability exists in all releases up to and including 9.6.4.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present, consistent with the fact that the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves delivering crafted input—such as URL parameters or custom content fields rendered by the theme—to a victim’s browser, with no special privileges required, making this a remote web‑based vulnerability.
OpenCVE Enrichment