Impact
The plugin contains an improper neutralization of user input during web page generation, allowing an attacker to inject and execute arbitrary scripts in the victim's browser. This reflected cross‑site scripting flaw can facilitate phishing, cookie theft, or defacement when users view the affected report page.
Affected Systems
Affecting the Anzar Ahmed Ni WooCommerce Sales Report Email plugin from its earliest versions through 3.1.4, which are now vulnerable if installed in any WordPress site.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. With an EPSS score below 1 %, exploitation opportunities are currently low but non‑zero, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, via a crafted URL or form that a user clicks or views, leading to reflected XSS in the victim’s browser. No elevated privileges or server‑side impact are described, so the risk is confined to client‑side compromise.
OpenCVE Enrichment
EUVD