Impact
The Aora theme for WordPress versions 1.3.19 and earlier contains an unauthenticated Cross‑Site Scripting flaw. Unsanitized input in the theme’s code allows attackers to inject arbitrary scripts that run in the browsers of visitors who load a page using the vulnerable theme. This can lead to session hijacking, credential theft, or defacement of the site.
Affected Systems
WordPress installations using the thembay Aora theme version 1.3.19 or earlier are affected. Users who have not upgraded to 1.3.20 or later remain vulnerable and must apply the update immediately.
Risk and Exploitability
The CVSS score of 7.1 marks this as high severity. Exploit probability is not quantified due to a missing EPSS score, and the vulnerability is not listed in CISA’s KEV catalog. Attackers do not need any form of privilege or authentication, and can target the site merely by delivering a malicious payload to a web page that uses the theme.
OpenCVE Enrichment