Impact
An unauthenticated attacker can exploit a reflected XSS flaw in the WordPress Urna theme when its version is 2.6.2 or older. The flaw allows injection of arbitrary client‑side scripts that run in the browser of any visitor to the affected site, potentially enabling cookie theft, session hijacking, defacement, or delivery of malicious payloads. This weakness is classified as CWE‑79, indicating an input validation weakness that fails to encode or filter user‑supplied data.
Affected Systems
The vulnerability is limited to installations of the Urna theme provided by thembay. Any WordPress site using Urna version 2.6.2 or earlier is affected. Versions 2.6.3 and newer contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as High. No EPSS score is available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user supplying malicious script payloads via a specially crafted request that the theme renders unsanitized.
OpenCVE Enrichment