Impact
A reflected cross‑site scripting flaw in the Bracketweb Voldor WordPress theme allows malicious input to be reflected back in web pages, enabling attackers to inject and execute arbitrary JavaScript in a victim’s browser. The vulnerability is a classic example of CWE‑79 and can compromise confidentiality and integrity by facilitating session hijacking, defacement, or credential theft. Attackers can exploit this flaw without needing special credentials, simply by crafting a URL or embedding malicious input where the theme renders it.
Affected Systems
WordPress sites that use the Bracketweb Voldor theme, versions from the first released build through 1.0.0 inclusive. No further version is currently identified as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact and medium exploitation complexity. With the EPSS score unavailable, the likelihood of exploitation is uncertain but the presence of a reflected XSS vector means attackers can target any user who visits a crafted page. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nonetheless, the attack path—sending a malicious link to a user or embedding a crafted URL in a content page—makes it straightforward for an attacker to exploit this flaw.
OpenCVE Enrichment