(:A cross-site scripting was reported in the Grifus theme for Wordpress.:A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.::A proof of concept is available.)