Impact
The Advanced Woo Search plugin contains a stored cross‑site scripting flaw within its aws_search_terms shortcode. Because the plugin fails to sanitize user‑supplied attributes and escape output, contributors or higher privileged users can submit malicious scripts that are stored and later executed in page contexts. This gives attackers the ability to run arbitrary JavaScript on visit, potentially leading to session hijacking, defacement, or credential theft when any site visitor loads the affected content.
Affected Systems
WordPress sites running the Advanced Woo Search – Product Search for WooCommerce plugin, versions 3.28 and earlier. Sites that have enabled the aws_search_terms shortcode exposed to authenticated contributors are at risk. The issue applies to all installations that have not yet upgraded beyond 3.28.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, but the EPSS score of <1% suggests a low probability of exploitation. The vulnerability requires authentication with contributor‑level access or higher, and the attacker must embed the malicious payload via the shortcode, which is then stored in the database. Because the payload runs when any user visits the affected page, the potential damage escalates if the site has a large visitor base, but overall risk remains limited until the plugin is updated or mitigated. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD