Impact
The Product Catalog Simple plugin for WordPress is vulnerable to stored cross‑site scripting through its show_products shortcode in all releases up to and including 1.7.11. The flaw is a CWE‑79 (Cross‑Site Scripting) vulnerability caused by insufficient sanitization of user‑supplied attributes, which allows an authenticated contributor or higher to inject arbitrary JavaScript that is persisted in the database and executed whenever any visitor views a page containing the shortcode. This can result in session hijacking, defacement, or execution of additional malicious payloads on the client side.
Affected Systems
WordPress sites that have the implecode Product Catalog Simple plugin installed with a version of 1.7.11 or earlier. The vulnerability exists across all platforms where the plugin is active.
Risk and Exploitability
The CVSS score of 6.4 denotes moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation at present. Because the attack requires authenticated access at contributor level or higher, an attacker must first compromise credentials or infiltrate a legitimate user account with those privileges. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD