Impact
The flaw is caused by an improper neutralization of input when generating web pages, which allows an attacker to inject malicious JavaScript that executes in the browser of anyone who views a crafted page. When successfully exploited, the injected script can hijack user sessions, steal cookies, deface content, or deliver malicious downloads. This is a client‑side weakness identified as CWE‑79.
Affected Systems
WordPress theme Designthemes Whistle – Sports Club is affected in all releases up to and including version 4.2. Versions newer than 4.2 are not known to contain the vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate level of risk. Because the vulnerability is remote and requires a user to visit a page or submit data that triggers the reflected XSS, the exploitability depends on the presence of such input vectors (e.g., search, comment, or URL parameters). The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. No public exploits have been reported, so the likelihood of active exploitation remains low to moderate, but it is not impossible, especially in high‑traffic sites.
OpenCVE Enrichment