Cross-Site Scripting Vulnerability in Electrician WordPress Theme by Vergatheme
CVE-2025-31055

7.1HIGH

What is CVE-2025-31055?

This vulnerability allows an attacker to inject malicious scripts into web pages viewed by users of the Electrician - Electrical Service WordPress theme. When a user interacts with the affected theme without adequate input validation, it leads to reflected XSS attacks, enabling the potential theft of sensitive information or session hijacking.

Affected Version(s)

Electrician - Electrical Service WordPress <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
CVE-2025-31055 : Cross-Site Scripting Vulnerability in Electrician WordPress Theme by Vergatheme