Impact
Improper neutralization of user input allows a reflected cross‑site scripting attack on the WordPress MyDecor theme. The vulnerability can cause malicious JavaScript to run in a visitor’s browser, potentially leading to session hijacking or defacement. This weakness is identified as CWE‑79.
Affected Systems
The vulnerability affects the skygroup MyDecor theme versions older than 1.5.9. Systems running any of these theme versions in a WordPress installation are at risk until the issue is patched.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high severity. Exploit availability is currently unknown, and the vulnerability is not listed in the KEV catalog. The most likely attack vector is external web traffic that can trigger the reflected XSS payload, so any public‑facing WordPress site using an affected theme presents a direct risk.
OpenCVE Enrichment