Impact
The UDesign theme includes user‑supplied input that is incorporated into web pages without proper escaping, allowing an attacker to inject and execute arbitrary JavaScript in a victim’s browser. This can enable session hijacking, credential theft, or site defacement.
Affected Systems
AndonDesign UDesign theme version 4.14.0 or earlier installed on WordPress sites.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential for exploitation if an attacker can supply reflected content; however, the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve remote delivery of malicious URLs or crafted input fields that reflect the data back to the user’s browser. The impact occurs only when the victim loads the vulnerable page, and it affects confidentiality and availability of user sessions.
OpenCVE Enrichment