Impact
An improper neutralization of input during web page generation allows attackers to inject malicious scripts that are reflected back to the user. The vulnerability is a classic reflected XSS attack and can lead to session hijacking, credential theft, or defacement of the website. The weakness is identified as CWE‑79, indicating insufficient input validation and output encoding.
Affected Systems
The Bracketweb Ogency WordPress theme is affected, versions from n/a through 1.0.0. All installations of the theme that have not been updated beyond 1.0.0 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not provided, but the lack of KEV listing suggests no known active exploitation yet. The likely attack vector is a crafted HTTP request containing malicious script payloads in reflected parameters or form fields. An attacker with vulnerable target exposure could exploit this without authentication, exposing the site to client‑side attacks.
OpenCVE Enrichment