Impact
The vulnerability is a Reflected XSS flaw due to improper neutralization of input in the WordPress plugin Order Audit Log for WooCommerce. This flaw allows an attacker to inject malicious scripts when the plugin generates pages that display user-supplied data, potentially leading to the theft of session cookies or other malicious actions in the victim’s browser. The weakness is classified as CWE-79.
Affected Systems
All WordPress sites running the Order Audit Log for WooCommerce plugin version 2.0 or earlier, developed by infosoftplugin, are affected. No other WordPress core components or plugins are impacted by this flaw.
Risk and Exploitability
The CVSS score of 7.1 signals moderate to high risk, while the EPSS score below 1% indicates a low likelihood of automated exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can craft a link containing malicious payloads that, when opened by users who view the vulnerable audit-log pages, will execute the script in the victims’ browsers. Because the exploit is reflected, it can be triggered from any URL containing the payload, making it easy for attackers to target a broad audience.
OpenCVE Enrichment
EUVD