Impact
The vulnerability allows an authenticated administrator to inject arbitrary JavaScript into the content of email templates. The injected script is stored by the plugin and executed each time customers view transactional emails. This flaw is an instance of improper output encoding (CWE‑79) and is reflected in a CVSS score of 4.4.
Affected Systems
The flaw exists in all versions of the Email Customizer for WooCommerce plugin up to and including 2.6.7. Users of the plugin on multi‑site WordPress installations where the unfiltered_html role capability is removed are impacted. The issue does not affect single‑site setups or instances where unfiltered_html remains enabled.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, and the EPSS score (<1%) suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires administrator privileges and the ability to edit email templates; once injected, the malicious script runs in the browsers of customers reading the email.
OpenCVE Enrichment