Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw present in all releases of the Contempoinc Real Estate 7 WordPress theme up to version 3.5.9. Attackers can inject arbitrary JavaScript into pages that display theme content, allowing them to run client‑side code in the context of any visitor who loads the affected page. The flaw arises from the theme rendering user‑supplied data without proper escaping and is classified as CWE‑79.
Affected Systems
All installations of the Contempoinc Real Estate 7 theme that are running version 3.5.9 or earlier are affected, regardless of the WordPress core or other plugins in use. Site administrators should verify the current theme version and upgrade to version 3.6.0 or newer, which contains the official fix.
Risk and Exploitability
The CVSS base score of 7.1 places the defect in the medium‑to‑high severity range. The EPSS score of less than 1% indicates a low overall probability of exploitation, yet the flaw is publicly reachable from unauthenticated users via normal web browsing. The vulnerability is not listed in the CISA KEV catalog. Because the threat is an unauthenticated XSS that can be triggered by any visitor to an affected page, attackers can run client‑side code in the context of the user’s browser without needing privileges.
OpenCVE Enrichment