Impact
The vulnerability is an improper neutralization of input that allows adversaries to store malicious scripts in the WooCommerce plugin’s product data. These scripts are later rendered when a user views the affected page, giving attackers the ability to execute arbitrary code in the context of the visitor’s browser session, potentially compromising the confidentiality and integrity of user data.
Affected Systems
VillaTheme Advanced Product Information for WooCommerce plugin is affected. All releases from the initial version up to and including 1.1.4 are vulnerable. No later versions are mentioned as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Attackers can inject scripts into product data that are subsequently executed when visitors access the affected pages, potentially compromising the confidentiality and integrity of client browser sessions.
OpenCVE Enrichment
EUVD