Impact
The WordPress plugin Product Table for WooCommerce, authored by Saiful Islam, contains an improper input neutralization flaw leading to reflected XSS. An attacker can embed malicious JavaScript into a crafted URL that the plugin echoes back into the page. Execution in the victim’s browser could allow exfiltration of session cookies, keylogging, or other client‑side attacks, compromising confidentiality and integrity of the user session.
Affected Systems
This vulnerability impacts all installations of the Saiful Islam Product Table for WooCommerce plugin with versions up to and including 4.0.3. Site administrators running the plugin on any WordPress site should thus consider themselves exposed.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity. EPSS below 1% suggests an unlikely large‑scale exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is remote and requires an attacker to craft a URL containing malicious input that is echoed by the plugin, which then runs in the victim’s browser. No privilege escalation or server‑side compromise is needed.
OpenCVE Enrichment
EUVD