Impact
An improper neutralization of script‑related HTML tags in the Kutethemes TechOne theme creates a Basic XSS condition that allows attackers to inject arbitrary shortcodes containing malicious code. These injected shortcodes can execute within the context of the site, giving a potential for defacement, data exfiltration, or further exploitation.
Affected Systems
WordPress installations running the TechOne theme from any version up to and including 3.0.3 are affected. This includes all earlier releases for which the theme version is not explicitly listed as safe.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3 (moderate) and an EPSS score of less than 1%, and it is not listed in the CISA KEV catalog. Attackers can exploit this remotely via the WordPress content‑editing interface that processes shortcodes, assuming they possess sufficient privileges to insert or edit post content. While the explosion likelihood is currently low, the potential impact remains significant for sites that use the legacy version of the theme.
OpenCVE Enrichment