Impact
The CozyStay theme for WordPress contains an unauthenticated cross‑site scripting vulnerability that allows attackers to inject malicious JavaScript into pages rendered by the theme. By placing arbitrary script payloads into areas of the site that are not properly sanitised, an attacker can execute code within a visitor’s browser, potentially leading to session hijacking, defacement, or theft of sensitive information. The weakness is a classic input‑validation flaw, classified as CWE‑79.
Affected Systems
WordPress installations running the CozyStay theme version 1.10.0 or earlier are affected. The vendor is LoftOcean and the product name is CozyStay. Users should review their WordPress theme version and ensure it is updated to 1.10.1 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact and the vulnerability is exploitable without authentication, making it accessible to any visitor who triggers the vulnerable code path. EPSS data is currently unavailable, but the lack of a KEV listing suggests it is not yet a widely leveraged exploit. The likely attack vector is remote, via a web request to a page that renders the vulnerable theme components. An attacker does not need privileged access to the site, raising the risk to all sites that feature CozyStay.
OpenCVE Enrichment