Impact
The Stock History & Reports Manager for WooCommerce plugin contains a stored Cross‑Site Scripting weakness in the alg_wc_stock_snapshot_restocked shortcode. An attacker who can authenticate as a contributor or higher can supply malicious attributes that are not properly sanitized or escaped, causing the plugin to persist user‑provided code. When an affected page is rendered, the injected script runs in the victim’s browser, potentially compromising credentials, defacing content, or stealing sensitive data.
Affected Systems
WordPress sites that have the Stock History & Reports Manager for WooCommerce plugin published by WPCodeFactory. Versions up to and including 2.2.2 are impacted. Sites with contributor‑level or higher authentication are required for exploitation.
Risk and Exploitability
The CVSS v3 base score of 6.4 indicates a moderate severity. The EPSS score is below 1 %, showing that real‑world exploitation is currently low but not impossible. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with contributor privileges to inject a payload via the shortcode attributes, which is then stored and later executed when the page containing the shortcode is viewed.
OpenCVE Enrichment