Impact
The vulnerability is an improper neutralization of input during web page generation, resulting in stored cross‑site scripting in the Sell Digital Downloads plugin. An attacker who can supply content to the plugin can inject arbitrary JavaScript that will execute whenever the affected page is viewed. This client‑side code can lead to session hijacking, defacement, or the delivery of malware to site visitors. The weakness is a classic stored XSS flaw classified under CWE‑79.
Affected Systems
Any WordPress site running the wpecommerce Sell Digital Downloads plugin up through version 2.2.7 is affected. The vulnerability is present in all releases from the earliest available until and including 2.2.7, so sites with any of those versions should be considered vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium to high severity for this flaw. The EPSS score of less than 1% suggests that the probability of real‑world exploitation is low at this time, and the vulnerability is not listed in CISA's KEV catalog. The CVE description does not specify authentication requirements, so it is unclear whether the attack can be performed by unauthenticated or only authenticated users. Based on the nature of stored XSS in a plugin, the most likely attack vector is the plugin’s data entry or administration interface, but this is inferred from the description rather than explicitly stated.
OpenCVE Enrichment
EUVD