Impact
The RT‑Theme 18 | Extensions plugin for WordPress contains an improper neutralization of input during web page generation, which allows a reflected Cross‑Site Scripting flaw. The flaw permits arbitrary JavaScript to execute in the context of a victim’s browser when a crafted request is reflected back in a page.
Affected Systems
WordPress sites that have installed the RT‑Theme 18 | Extensions plugin from stmcan, in any version up to and including 2.5, are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1 % points to a low likelihood of exploitation as of now. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be triggered by a user visiting a maliciously crafted URL, without requiring authentication.
OpenCVE Enrichment