Impact
The Tranmautritam TheFox WordPress theme, versions 3.9.76 or earlier, contains a reflected cross‑site scripting flaw (CWE‑79). The theme fails to sanitize user‑supplied data that is echoed back to the browser, allowing an attacker to embed arbitrary JavaScript that is reflected to a victim’s browser. The description indicates the flaw is unauthenticated, meaning any user can submit data that will be reflected.
Affected Systems
Any WordPress site that activates the Tranmautritam TheFox theme version 3.9.76 or earlier is affected. The vulnerability does not depend on other plugins or the core version; it exists purely when the theme is active and processes untrusted input.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity, while the EPSS score of less than 1% indicates a low yet realistic exploitation probability. Because no authentication is required, the likely attack vector is an unauthenticated attacker sending a crafted request—such as a malicious URL or form submission—that contains script payloads, which the theme then reflects to the victim’s browser. The vulnerability is not listed in CISA’s KE catalog but the high CVSS score warrants timely remediation.
OpenCVE Enrichment