Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress WoodMart Theme up to version 8.5.3. This flaw allows an attacker to inject and execute arbitrary JavaScript in the page viewed by any visitor. The potential impact includes site defacement, session hijacking, or phishing attacks against users, compromising the confidentiality and integrity of user interactions. The weakness aligns with CWE‑79, a classic reflected or stored XSS vulnerability.
Affected Systems
Affected product is the WordPress WoodMart Theme from Xtemos, version 8.5.3 or earlier. Administrators must verify and apply the available update to 8.5.4 or newer, which contains the patch.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, so the exact exploitation likelihood cannot be quantified, but the flaw is unauthenticated and does not require elevated privileges, meaning an attacker can easily orchestrate the exploit. The vulnerability is not currently listed in CISA KEV. Likely attack vectors involve a crafted URL or input field that the theme renders without proper escaping, allowing a malicious payload to be executed when a user visits the affected page.
OpenCVE Enrichment