Impact
ProgressionStudios Vayvo theme contains an improper neutralization of input during web page generation, allowing malicious scripts to be reflected in the browser. An attacker can embed JavaScript into a URL or form input that is echoed back in the response, potentially enabling data theft, session hijacking, or unauthorized actions. The weakness aligns with CWE‑79, a client‑side vulnerability that compromises user trust and privacy.
Affected Systems
WordPress sites that utilize the Vayvo Media Streaming & Membership theme from any version prior to 6.8 are affected. This includes all installations of the theme where the version string indicates < 6.8, as the issue is present across all earlier releases.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑high severity. No EPSS data is available, but reflected XSS is a well‑known attack vector that can be executed via a simple crafted URL and does not require special privileges. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploitation, yet the attack surface is broad and the impact on end‑users can be substantial if a malicious script is delivered.
OpenCVE Enrichment