Impact
A Reflected XSS flaw exists in the filters‑scheda‑didattica.php file of the Design Scuole Italia WordPress theme. An attacker can supply a malicious value for the archive parameter in a URL, which is then echoed by the template without proper escaping. When a user clicks the crafted link, arbitrary JavaScript executes in that user’s browser, potentially allowing credential theft, session hijacking, or defacement. The weakness is identified as CWE‑79 and carries a CVSS score of 5.1, indicating a moderate risk to confidentiality and integrity of affected users.
Affected Systems
The vulnerability affects installations of the WordPress theme Developers Italia:design‑scuole‑wordpress‑theme. All sites that have not applied the vendor’s fix are susceptible; the exact impacted files are filters‑scheda‑didattica.php and its associated template where the archive variable is output.
Risk and Exploitability
The flaw is exploitable via a simple URL manipulation and does not require authentication or any special privileges on the site. Because the attacker controls the URL, any user who visits the link can be victimized. The EPSS score of 0.00395 represents a very low but non‑zero likelihood of exploitation in the current threat landscape. The CVSS score of 5.1 reflects a moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. Mitigating the issue is essential to prevent cross‑site scripting attacks against site visitors.
OpenCVE Enrichment