Impact
The vulnerability is an improper neutralization of input during web page generation. The Woo Store Mode plugin reflects unsanitized user input in HTML output, allowing malicious scripts to run in the browser of any user who visits a crafted page. This could enable tampering with page content, session hijacking, or phishing attacks.
Affected Systems
The affected product is the Woo Store Mode plugin developed by simonhunter. Versions from the earliest release through 1.0.1 are vulnerable; thus any installation of version 1.0.1 or earlier is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score is less than 1%, suggesting low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web request that includes malicious query parameters, which the plugin echoes back unescaped into the page. An attacker can exploit this by crafting a URL sent to unsuspecting users, causing the browser to execute injected scripts.
OpenCVE Enrichment
EUVD