Impact
Unauthenticated Cross Site Scripting (CWE-79) exists in WordPress Coaching Theme versions up to 3.9.2, allowing an attacker to inject arbitrary scripts into pages viewed by site visitors. This can lead to session hijacking, theft of sensitive data, defacement, or further exploitation of users who load malicious content in their browsers. The flaw endangers confidentiality, integrity and availability of the web application and its users.
Affected Systems
The vulnerability affects WordPress installations that are using the Coaching Theme from ThimPress, specifically all versions 3.9.2 and earlier. Any site that has not upgraded the theme is at risk.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered moderate severity, and the EPSS score of less than 1% indicates that, at present, exploitation is unlikely to be widespread. The flaw is unauthenticated and remote, meaning an attacker can inject the payload without needing to log in. The theme does not appear in the CISA KEV list, further reducing the perceived threat at this time. Nonetheless, based on the description it is inferred that the attack vector is public web input; it is still possible that an attacker could use the vulnerability for phishing or credential theft if they can convince users to interact with a malicious page.
OpenCVE Enrichment