Impact
The affected theme contains an improper neutralization of input during web page generation, resulting in reflected cross‑site scripting. This flaw allows an attacker to embed malicious scripts that execute in a victim’s browser when a crafted URL is visited, enabling session hijacking, credential theft, or the injection of fraudulent content.
Affected Systems
The vulnerability impacts THEWP Digital Solutions News Theme V8 versions up to 16.06.2026 inclusive. Users running any version before the release of a fixed build are susceptible.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity, and the EPSS score of less than 1% implies a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Reflected XSS attacks typically require a victim to click a malicious link or be tricked into viewing a crafted page, so the threat is operationally limited to the user’s browser. However, because the payload runs with the victim’s privileges, the attack can compromise data confidentiality and integrity.
OpenCVE Enrichment