Impact
An unauthenticated Cross‑Site Scripting flaw is present in Contempoinc Real Estate 7 WordPress theme versions 3.5.9 and earlier. The vulnerability exists because the theme displays user‑supplied data without proper escaping, allowing attackers to inject arbitrary JavaScript into any page that renders the theme content. The injected code runs in the visiting browser’s context and can lead to credential theft, session hijacking, or other client‑side attacks, thereby affecting user confidentiality and integrity.
Affected Systems
All installations of the Contempoinc Real Estate 7 WordPress theme version 3.5.9 or earlier are affected. The flaw resides in the theme’s rendering of user‑supplied content and is independent of additional plugins or WordPress core modifications. Site administrators should verify that the active theme is 3.6.0 or newer and apply the update promptly.
Risk and Exploitability
The CVSS base score of 7.1 places this vulnerability in the medium‑to‑high severity range. The EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis, yet the vulnerability is publicly reachable from unauthenticated users simply by browsing the site. Based on the description, the likely attack vector is any external web user visiting a page that renders theme content. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment