Impact
This vulnerability is an unauthenticated Cross‑Site Scripting (CWE‑79) flaw that allows an attacker to inject and execute arbitrary script code within pages served by the Kids Life | Children School WordPress theme version 5.2 or earlier. The injected script runs in the visitor’s browser context, allowing malicious actions when a user views those pages.
Affected Systems
The issue affects sites using Designthemes Kids Life | Children School WordPress theme versions 5.2 and lower.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk, while the EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw is unauthenticated, any visitor to a page using the vulnerable theme can trigger it; no special privileges are required. The vulnerability is not listed in CISA KEV, so no active exploits have been reported.
OpenCVE Enrichment