Impact
Improper neutralization of input in the Shipdeo plugin allows reflected XSS. Based on the description, it is inferred that an attacker could inject arbitrary script code that will execute in visitors’ browsers, potentially leaking session data, hijacking accounts, or defacing the site. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites running the Shipdeo WooCommerce plugin version 1.2.8 or earlier are affected. Any installation that loads this plugin with a vulnerable version is exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high impact, while the current EPSS of under 1 % suggests low likelihood of exploitation observed so far. The vulnerability is not listed in the CISA KEV catalog. The CVE does not specify the exact attack vector, but it is likely that a malicious link or crafted URL that the victim clicks could trigger the reflected script, requiring user interaction.
OpenCVE Enrichment
EUVD