Impact
Unpatched versions of the Agrion WordPress theme accept user input without proper filtering, allowing attackers to inject malicious scripts that run in the browsers of visitors. This reflected XSS flaw can be leveraged to steal session cookies, deface content, or redirect users to phishing sites, thereby compromising confidentiality and integrity of user data.
Affected Systems
WordPress sites that have installed bracketweb’s Agrion theme version 1.0.0 or earlier are vulnerable. Any website that relies on this theme for rendering page content must be examined.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑to‑moderate risk. Although an EPSS score is not available, the lack of authentication requirement and the widespread use of WordPress themes suggest that exploitation is practical. The vulnerability is not currently listed in the CISA KEV catalog, but its impact justifies prompt remediation. Attackers can trigger the flaw by crafting URLs or form inputs that the theme echoes without sanitization.
OpenCVE Enrichment