Impact
An improper neutralization of input during web page generation allows a reflected XSS attack in the Bracketweb Treck theme. The flaw enables an attacker to inject malicious scripts into the output of web pages that are viewed by targeted users. This can lead to session hijacking, defacement, or phishing for credentials if the attacker is able to trick users into executing the injected script. The weakness is identified as CWE‑79 for cross‑site scripting.
Affected Systems
The vulnerability affects the Bracketweb Treck WordPress theme in all releases up to and including version 1.0.0. Any WordPress installation employing Treck in these versions is potentially vulnerable and should be reviewed for presence of the affected theme.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. EPSS data is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Although a specific exploitation scenario is not detailed in the advisory, the nature of reflected XSS strongly suggests that the attack vector involves a crafted URL or form input that is reflected back to the victim’s browser. If an attacker can trick a user into visiting such a URL, they can execute arbitrary scripts with the user’s browser context.
OpenCVE Enrichment