Impact
An attacker can inject malicious JavaScript into pages rendered by the Gaea WordPress theme because input is not properly neutralized during page generation. The reflected XSS flaw allows code execution in the victim’s browser, enabling session hijacking, credential theft, or site defacement. This weakness is a classic cross‑site scripting vulnerability classified as CWE‑79.
Affected Systems
The vulnerability affects all releases of the imithemes Gaea theme earlier than version 3.8. No further sub‑version detail is provided, so any theme version below 3.8 is considered vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity with a moderate exploitability. The EPSS score is not available. This flaw is not listed in the known exploited vulnerabilities catalog. Attackers can exploit it by embedding a malicious payload in a URL or form input and persuading a user to click the link or submit the input, requiring only user interaction. The risk is significant for sites using the affected theme, especially if user‑generated content is not sanitized.
OpenCVE Enrichment