Impact
The Grand Photography theme contains an unauthenticated reflected XSS flaw that allows an attacker to inject arbitrary JavaScript into pages rendered by a victim’s browser. This can enable session hijacking, phishing, or the execution of malicious code in the user’s context. The vulnerability originates from unvalidated input that is reflected directly into the page output. This flaw is identified as CWE-79.
Affected Systems
The issue affects all installations of the Grand Photography theme by ThemeGoods on WordPress up to and including version 5.7.8. Sites running any older version of the theme are therefore vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the flaw presents a significant risk. The EPSS score is less than 1%, indicating a low current exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is a crafted URL that a user clicks or is redirected to, triggering the reflected script. No authentication or elevated privileges are required to exploit this flaw.
OpenCVE Enrichment