Impact
The vulnerability arises from improper neutralization of input during web page generation (CWE‑79), permitting reflected cross‑site scripting in the "Samex" and "M.Anh" WordPress themes. A malicious attacker can inject arbitrary JavaScript that is executed in the browser of any visitor to a page rendering the unfiltered input. This can lead to cookie theft, session hijacking, defacement, or further propagation of malware, impacting the confidentiality, integrity, and availability of user interactions on the affected sites.
Affected Systems
WordPress sites that install either the snstheme Samex Clean, Minimal Shop WooCommerce WordPress Theme (versions any up to and including 2.5) or the snstheme M.Anh Fashion WooCommerce WordPress Theme (any up to and including 1.7). No other themes are specified as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability that can be exploited from any network. The EPSS score is not available, but the lack of listing in the CISA KEV catalog suggests no known widespread exploitation. The attack vector is reflected XSS, typically triggered by a crafted URL or form input that the theme echoes back without sanitization. An attacker with web‑access to the site can easily craft a malicious link and trick a user into clicking it, leading to the execution of arbitrary JavaScript in the victim’s browser.
OpenCVE Enrichment