Impact
The vulnerability is a reflected XSS flaw in the NativeChurch WordPress theme up to version 4.8.8.2. It allows an unauthenticated attacker to inject arbitrary client‑side scripts that are reflected in page output. The flaw can be triggered by supplying malicious input through a URL or other user‑controlled parameter. No authentication is required, and the vulnerability does not provide persistence beyond the victim’s browser session or compromise the WordPress server.
Affected Systems
The NativeChurch theme developed by iThemes is affected. All releases of the theme up to and.8.8.2 contain the vulnerability; versions after that release are not confirmed to be affected and should be verified against the vendor’s patch notes. Based on the release information, it is inferred that later versions may not contain the flaw.
Risk and Exploitability
The CV a substantial impact for an XSS flaw, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw without authentication by sending a victim a specially crafted URL containing malicious input; the payload is then reflected in the page response and executed when the page loads in the user’s browser. Based on the nature of reflected XSS, the vulnerability does not provide persistence beyond the victim’s session nor does it compromise the WordPress server.
OpenCVE Enrichment