Impact
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows a DOM-Based XSS flaw. The vulnerability arises when the theme fails to sanitize user‑provided data before injecting it into the page’s DOM. Based on the description of DOM‑based XSS, it is inferred that an attacker could inject arbitrary JavaScript that would execute in the victim’s browser, potentially allowing information disclosure, session hijacking, or other malicious actions.
Affected Systems
The vulnerability affects the Xtemos WoodMart WordPress theme in all releases prior to version 8.3.8. WordPress sites that have not upgraded the theme remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available, so the exploitation probability is unknown. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is via any user input or URL parameters that the WoodMart theme processes without proper sanitization, so any user who can submit data to the site could trigger the XSS attack.
OpenCVE Enrichment