Impact
The Tranmautritam TheFox theme for WordPress version 3.9.76 or earlier contains an unauthenticated reflected cross‑site scripting flaw (CWE‑79). The analysis indicates that the theme does not sanitize user‑supplied data that is echoed back to the browser, and this conclusion is inferred from the description. This flaw allows an attacker to inject and execute arbitrary JavaScript in the browser of a vulnerable page, enabling client‑side code execution.
Affected Systems
Any WordPress installation that is running the Tranmautritam TheFox theme version 3.9.76 or earlier is susceptible, regardless of the core WordPress version or other plugins used. The vulnerability affects all sites that activate the theme and display content generated by it.
Risk and Exploitability
Based on the description, the likely attack vector is an unauthenticated attacker submitting malicious input that the theme reflects back in a browser‑rendered page. The CVSS score of 7.1 indicates high severity, with no authentication required to exploit the flaw. The EPSS score is less than 1 %, implying a very low but real‑world exploitation. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment