Impact
Improper neutralization of user input during page generation enables reflected cross‑site scripting. An attacker can insert malicious scripts into URL parameters that the plugin echoes back without escaping, potentially allowing arbitrary script execution in the victim’s browser.
Affected Systems
All installations of the tahminajannat "URL Shortener | Conversion Tracking | AB Testing | WooCommerce" plugin running version 9.0.2 or earlier are affected, because the vulnerability is present through that version.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, while the EPSS score of < 1 % shows a low probability of exploitation as of now. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely need to entice a user to click a crafted link containing malicious payloads; no elevated privileges beyond a normal visitor are required for exploitation.
OpenCVE Enrichment
EUVD