Impact
Improper neutralization of input during web page generation (CWE‑79) in the ThemeGoods Architecturer theme allows reflected Cross‑Site Scripting. Based on typical outcomes of such attacks, an attacker could inject malicious scripts that are echoed back to users, potentially leading to cookie theft, session hijacking, or other client‑side compromise of site visitors.
Affected Systems
The flaw affects any installation of the ThemeGoods Architecturer theme for WordPress with a version earlier than 3.9.5. All such versions lack the required input sanitization that was introduced in 3.9.5.
Risk and Exploitability
The base CVSS score of 7.1 indicates a high severity risk. The EPSS score of less than 1% suggests a low probability of exploitation at present. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Likely attack vector is reflected XSS triggered by a malicious link or input that the theme echoes without proper encoding, requiring an attacker to lure a user to a crafted URL or form input to trigger the script.
OpenCVE Enrichment