Impact
The vulnerability is a reflected Cross‑Site Scripting flaw in the WordPress MediCenter – Health Medical Clinic theme that allows an attacker to inject malicious script into pages viewed by users. Because the theme fails to neutralize user‑supplied input before outputting it, an attacker can execute arbitrary JavaScript in the victim's browser, potentially exposing cookies, hijacking sessions, or delivering further malware. This weakness corresponds to CWE‑79, Improper Neutralization of Input.
Affected Systems
Affected systems include the QuanticaLabs MediCenter – Health Medical Clinic WordPress theme, for all releases from its initial version through to and including version 14.9. A site that has not upgraded beyond 14.9 exposes the reflected XSS risk.
Risk and Exploitability
The issue carries a CVSS score of 7.1, indicating high severity. Its EPSS score is less than 1 %, suggesting low but non‑zero probability of exploitation in the wild. The vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be a crafted URL or form input that the theme displays without sanitization; a malicious link embedded in a post or widget could trigger the script when clicked by a user.
OpenCVE Enrichment