Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows attackers to inject arbitrary JavaScript into pages rendered by the AW WooCommerce Kode Pembayaran WordPress plugin. This issue is classified as CWE‑79 and permits reflected XSS when a maliciously crafted input is reflected back in the HTML output. An attacker can cause client‑side scripts to run when a user visits a page that contains the manipulated input.

Affected Systems

WordPress installations that have the AW WooCommerce Kode Pembayaran plugin from any version prior to 1.1.5, specifically all releases up through 1.1.4, are affected. The plugin is distributed by agenwebsite and is commonly used on e‑commerce sites that process payments.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑to‑high risk level. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario where a crafted URL or form parameter is embedded in a page; no user authentication is required, so any visitor to the site could be affected. Upon successful exploitation, malicious code could execute in the victim’s browser when they view a page containing the crafted input.

Generated by OpenCVE AI on May 2, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AW WooCommerce Kode Pembayaran plugin to the latest available version (>= 1.1.5) that contains the XSS fix.
  • If an update cannot be applied immediately, add a Content Security Policy header that disallows inline scripts or restricts script sources to trusted origins.
  • Reduce the exposure by disabling the plugin on production sites that do not require it, or limit access to the plugin’s pages to administrators only.

Generated by OpenCVE AI on May 2, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5761 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran allows Reflected XSS. This issue affects AW WooCommerce Kode Pembayaran: from n/a through 1.1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran allows Reflected XSS. This issue affects AW WooCommerce Kode Pembayaran: from n/a through 1.1.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran allows Reflected XSS. This issue affects AW WooCommerce Kode Pembayaran: from n/a through 1.1.4.
Title WordPress AW WooCommerce Kode Pembayaran plugin <= 1.1.4 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:09.188Z

Reserved: 2025-01-16T11:24:48.263Z

Link: CVE-2025-23450

cve-icon Vulnrichment

Updated: 2025-03-03T15:56:57.642Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:35.780

Modified: 2026-06-17T08:54:28.020

Link: CVE-2025-23450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T04:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')