Impact
The Premmerce WooCommerce Customers Manager plugin contains a reflected cross‑site scripting flaw that allows any user to inject unwanted JavaScript via the 'money_spent_from', 'money_spent_to', 'registered_from', and 'registered_to' parameters in all versions up to 1.1.14. The vulnerability is caused by insufficient input sanitization and output escaping. An attacker who can trick an administrator into loading a crafted link can cause the browser to execute the injected script, potentially leading to session hijacking, credential theft, or other client‑side attacks. The weakness is catalogued as CWE‑79.
Affected Systems
This flaw affects WordPress installations running Premmerce WooCommerce Customers Manager version 1.1.14 or earlier. The affected component is the admin interface that processes the four query parameters mentioned above.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS of less than 1% suggests a low likelihood of exploitation at the present time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The most likely attack vector is a phishing style attack, where an unauthenticated attacker directs an admin to a malicious link containing the crafted parameters. The administrator’s browser would then execute the injected script.
OpenCVE Enrichment