Impact
Improper neutralization of user-supplied input during web page generation in the JanStudio Gecko theme allows reflected cross-site scripting. This flaw permits an attacker to inject malicious payloads, potentially executing arbitrary client‑side scripts or stealing sensitive data when a victim visits a crafted URL.
Affected Systems
WordPress sites running the JanStudio Gecko theme up to and including version 1.9.8 remain vulnerable. All releases from the earliest available until 1.9.8 are affected.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is classified as high impact. Its EPSS of less than 1% indicates that actual exploitation remains unlikely at present. The vulnerability is not yet listed in CISA's KEV catalog. Attackers could exploit it via a crafted URL or malicious link delivered to users, leveraging the reflected XSS vector. Based on the description, it is inferred that the attack vector involves sending users a specially crafted URL that incorporates malicious payloads into the theme’s query parameters. Applying an update to the theme or implementing a WAF rule to block reflected XSS payloads is recommended for mitigation.
OpenCVE Enrichment