Impact
The SEOWP WordPress theme version 3.12.2 and older contain an unauthenticated Cross‑Site Request Forgery flaw that enables the injection of malicious script code into the site’s content. The injected code is persisted and executed on every page load that displays the compromised content, resulting in a stored XSS condition.
Affected Systems
WordPress sites that use the SEOWP theme from BlueAstralThemes, named SEOWP, with any version up to and including 3.12.2 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating moderate to high severity, and has an EPSS score of less than 1%, signifying a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is unauthenticated CSRF, meaning; based on the description it is inferred that the attacker would target a visitor who is already authenticated and has permission to modify content.
OpenCVE Enrichment