Impact
An unauthenticated cross‑site scripting flaw exists in the Manual – Documentation, Knowledge Base & Education WordPress Theme up to version 7.5.4. The vulnerability allows an attacker to insert arbitrary JavaScript into pages generated by the theme, enabling the execution of scripts in the browsers of site visitors. Because no authentication is required, any user who accesses a vulnerable page can trigger the flaw.
Affected Systems
All installations of the PixelaceHQ Manual theme version 7.5.4 and earlier are affected. Sites that enable or activate this theme are at risk until the theme is updated or removed.
Risk and Exploitability
The CVSS score is 7.1, indicating a high impact, while the EPSS score of less than 1 % suggests that exploitation opportunities in the wild are currently low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by simply visiting a page that includes the vulnerable rendering logic; no credentials or additional access privileges are necessary, making the vulnerability readily usable against site visitors and the site itself.
OpenCVE Enrichment