Impact
An unauthenticated cross‑site scripting flaw exists in the TieLabs Jannah WordPress theme versions up to 7.6.5. The flaw allows an attacker to inject and execute arbitrary JavaScript in the context of any visitor’s browser that loads a page rendered by the vulnerable theme. This vulnerability is classified as CWE‑79.
Affected Systems
The theme that is affected is the TieLabs Jannah WordPress theme, specifically any installation using version 7.6.5 or earlier. Users who have not upgraded the theme to a later release are at risk.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity rating. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so exploitation frequency is uncertain. Because the flaw can be triggered without authentication and only requires a visitor to load a page rendered by the affected theme, attackers can embed malicious scripts directly into the page content.
OpenCVE Enrichment