Impact
The vulnerability is an improper neutralization of input during web page generation in the G5Theme Wolverine Framework plugin, permitting reflected cross‑site scripting (CWE‑79). The flaw could allow an attacker to inject arbitrary JavaScript that is executed in the browser of any visitor to a crafted URL; it is inferred that such injection could be used for further malicious actions.
Affected Systems
All releases of G5Theme Wolverine Framework from its earliest version up through and including version 1.9 are affected. WordPress sites that have installed the plugin within this version range are vulnerable until the plugin is upgraded or patched.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is remote and does not require prior authentication, since the flaw is triggered by user-supplied URL or input that is reflected to the browser.
OpenCVE Enrichment