Impact
The vulnerability arises from improper neutralization of user input before rendering it in a web page. An attacker can supply malicious JavaScript in a request that the plugin reflects back into the page, allowing the script to execute in the victim’s browser. The impact can include execution of arbitrary code in the context of the site, credential theft, or defacement. The weakness is classified as CWE‑79.
Affected Systems
This flaw applies to the GlobalPayments WooCommerce WordPress plugin in all releases from initial release through version 1.13.2. The plugin is widely used for processing payments on WordPress-powered e‑commerce sites.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity risk. The EPSS indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a web browser via a crafted URL or input field, as the defect involves reflected input. Because the flaw requires the victim to visit a maliciously constructed page, it typically does not affect remote servers directly but enables client‑side attacks.
OpenCVE Enrichment
EUVD