Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation. If an attacker can insert malicious script into the stored content, it will execute in the browser context of any visitor, enabling malicious code to run on the site. This can compromise confidentiality, integrity, or availability of user data and the site’s reputation.
Affected Systems
Get Bowtied Product Blocks for WooCommerce plugin, all releases from the first version through 1.9.1 are affected. The flaw exists in the way product‑block content is rendered, allowing script injection wherever the problematic fields are used.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate severity, and the EPSS score of less than 1 percent indicates a low probability of exploitation in the near term. The flaw is not listed in the CISA KEV catalog, but because it is a stored XSS the risk to authenticated or content‑editing users is higher than a purely client‑side issue. Exploitation would likely involve inserting a script tag into a product description or similar field that is then rendered in the public product page.
OpenCVE Enrichment
EUVD