Impact
Improper neutralization of user input during web page generation allows an attacker to insert malicious scripts that are echoed back in the content served to a victim’s browser. This reflected XSS is identified as CWE‑79.
Affected Systems
The vulnerability affects WordPress sites that use the Porto theme from p‑themes. All releases up to and including version 7.6.2 are vulnerable, so any site running Porto 7.6.2 or earlier should be considered at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high severity, while the EPSS rating of less than 1 % suggests a low likelihood of exploitation at this time. The issue is not listed in CISA’s KEV catalog. Attackers can exploit this flaw by crafting a malicious URL or form input that is reflected in the rendered page, enabling a remote, unauthenticated XSS attack on any user who loads the page.
OpenCVE Enrichment