Impact
The Product Puller plugin contains an improper neutralization of user input during web page generation, leading to a reflected XSS vulnerability. This flaw (CWE‑79) allows an attacker to inject malicious scripts into responses that echo user‑controlled data, enabling hijacking of user sessions, credential theft, or defacement of the site. The vulnerability is exploitable through attacker‑controlled input that is reflected in the browser without proper sanitization.
Affected Systems
WordPress sites using Kemal YAZICI’s Product Puller plugin version 1.5.1 or earlier are affected. No other product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑moderate severity, while the EPSS score of less than 1 % suggests low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would typically trigger the flaw by crafting a URL or form input that includes malicious script content, which the plugin then reflects back to the visitor's browser.
OpenCVE Enrichment