Impact
The vulnerability is a stored cross‑site scripting flaw caused by missing escape handling in the custom location field of the YOOtheme Pro extension. An attacker who can supply input to this field can persist malicious JavaScript that will execute whenever a privileged user views the affected page. This type of flaw is classified under CWE‑79 and compromises the confidentiality and integrity of user sessions or can be used for defacement.
Affected Systems
The flaw exists in the YOOtheme Pro extension for Joomla, versions 1.0.0 through 5.0.41. Any website running the extension within that version range is potentially impacted.
Risk and Exploitability
With a CVSS score of 7.5 the issue is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the impact is significant for any authenticated user who has write access to the custom location field. The attack requires legitimate authorized credentials to add or edit content, after which the stored payload will run in the browsers of other privileged users who view the page.
OpenCVE Enrichment