Impact
The vulnerability is an improper neutralization of input during web page generation, which leads to a reflected XSS flaw in the Kriesi Enfold WordPress theme. An attacker can deliver a crafted URL or payload that is included unfiltered into a web page, allowing the execution of arbitrary JavaScript within the victim’s browser context.
Affected Systems
All installations of the Kriesi Enfold WordPress theme from the initial version up to and including 8.0 are affected. Sites that have not updated beyond 8.0 are vulnerable.
Risk and Exploitability
The CVSS base score of 5.8 indicates moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a crafted URL and can be performed by an unauthenticated user, making it a remote, client‑side attack that relies on reflected input.
OpenCVE Enrichment