Impact
An unauthenticated reflected cross‑site scripting vulnerability exists in the DesignThemes LMS WordPress theme up to version 9.7. User‑controlled data is echoed back without proper encoding, enabling an attacker to inject JavaScript that will execute in the browser of anyone who views the affected page. This is an input validation weakness identified as CWE‑79.
Affected Systems
The vulnerability affects only the DesignThemes LMS WordPress theme, versions 9.7 and earlier; no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests that exploitation attempts are unlikely, and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, relying on a crafted request that triggers the theme to echo malicious browser, because the flaw is unauthenticated and reflected.
OpenCVE Enrichment