Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation. Malicious JavaScript can be injected into content that is stored by the plugin, and later executed in the browsers of site visitors. This enables defacement, cookie theft, session hijacking or other client‑side attacks that compromise confidentiality and integrity of user data.
Affected Systems
Affected systems are WordPress sites that use the HasThemes Free WooCommerce Theme 99fy Extension (99fy-core) plugin version 1.2.8 or earlier. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of <1% suggests a very low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to submit input that is stored by the plugin, such as through content submission pages. When that stored input is later rendered to visitors, the stored malicious script is executed.
OpenCVE Enrichment
EUVD