Impact
The vulnerability is a flaw in MojofyWP Product Carousel For WooCommerce – WoorouSell that allows stored cross‑site scripting. Malicious input that is entered into the plugin’s content fields is rendered without proper encoding, causing the browser to execute injected scripts when users view the affected content.
Affected Systems
The affected product is the WoorouSell plugin for WordPress provided by MojofyWP, specifically any installation of version 1.1.0 or older. WordPress sites using this plugin to display product carousels for WooCommerce are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker submitting malicious payloads through the plugin’s content fields, which are stored and later rendered on the front‑end without sanitization.
OpenCVE Enrichment
EUVD