Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rajib.dewan Opencart Product in WP opencart-product-in-wp allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through <= 1.0.1.
Published: 2025-01-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting (XSS) flaw (CWE‑79) that arises from improper neutralization of user‑supplied input during dynamic web page generation in the Opencart Product in WP plugin. When an attacker crafts a URL or other input that is displayed by the plugin, the malicious payload is echoed directly into the browser, allowing the execution of arbitrary JavaScript. This can lead to theft of session cookies, defacement of the site, or redirecting users to phishing pages.

Affected Systems

The flaw exists in all releases of the rajib.dewan Opencart Product in WP plugin up through version 1.0.1. Sites running the plugin at any version up to and including 1.0.1 are affected. The product is distributed as a WordPress plugin.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑moderate severity, while the EPSS score of less than 1% suggests that active exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, and no known active exploits have been reported. Based on the description, it is inferred that an attacker would need to lure a victim to a specially crafted URL – user interaction is required – to deliver the reflected XSS payload. Once the payload executes, the attacker can hijack the victim’s session or steal sensitive data. The overall risk is moderate but should be mitigated promptly.

Generated by OpenCVE AI on May 2, 2026 at 06:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Opencart Product in WP plugin to a version newer than 1.0.1 or remove the plugin entirely.
  • Implement proper output escaping and input validation within the plugin code to ensure all user data is neutralized before rendering.
  • Deploy a web application firewall rule set that detects and blocks suspicious script payloads in query strings or form submissions.

Generated by OpenCVE AI on May 2, 2026 at 06:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2735 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rajib.dewan Opencart Product in WP opencart-product-in-wp allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 07 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Rajib Dewan Opencart Product in WP allows Reflected XSS.This issue affects Opencart Product in WP: from n/a through 1.0.1.
Title WordPress Opencart Product in WP plugin <= 1.0.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:10:59.634Z

Reserved: 2025-01-03T13:16:33.553Z

Link: CVE-2025-22335

cve-icon Vulnrichment

Updated: 2025-01-07T17:27:39.477Z

cve-icon NVD

Status : Deferred

Published: 2025-01-07T16:15:42.703

Modified: 2026-06-17T08:46:33.967

Link: CVE-2025-22335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:45:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')