Impact
The vulnerability is an improper neutralization of input during web page generation that permits DOM‑based XSS in the ThemeGoods Photography WordPress theme. An attacker can inject malicious scripts that will execute in the browsers of visitors to the site. This flaw allows the attacker to run code in the context of the theme, potentially affecting the integrity of the user experience.
Affected Systems
ThemeGoods Photography theme versions older than 7.7.6 installed in WordPress sites are affected. This includes all installations that have not applied the latest patch.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers most likely target the vulnerability by crafting a URL or posting content that triggers the DOM‑based XSS, and the exploit requires a user’s browser to load the page where the input is reflected.
OpenCVE Enrichment