Impact
XSS in the WordPress Graphene theme versions up to 2.9.4 allows an attacker to inject malicious JavaScript into pages that are viewed by site visitors. The flaw is an XSS vulnerability (CWE-79) triggered by malicious subscriber data and can execute arbitrary scripts in the context of the site, potentially defacing content, stealing cookies or hijacking sessions.
Affected Systems
The WordPress Graphene theme (silverks:Graphene) is affected in all releases with a version number of 2.9.4 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium level of risk. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known, active exploits. The likely attack vector is a web-based, remote exploitation that relies on a victim loading a page containing malicious input provided by a subscriber account. Exploitation probably requires user interaction but can be mitigated by preventing subscriber data from rendering unescaped.
OpenCVE Enrichment