Impact
The vulnerability is a stored cross‑site scripting flaw that allows the plugin to process malicious input without proper encoding during web page generation. An attacker who can inject such input could have the browser execute arbitrary JavaScript in the context of the site, potentially affecting any user who views the affected pages.
Affected Systems
WordPress installations running the Woo Update Variations In Cart plugin version 0.0.9 or earlier, as distributed by codingkart.
Risk and Exploitability
The CVSS score of 6.5 classifies this flaw as a moderate severity issue, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. Based on the description, exploitation would involve injecting malicious data through the plugin’s input processing, leading to a stored XSS when other users view the data or the cart. The attack vector is web‑based and requires interaction with the plugin’s data fields; no remote code execution path is indicated.
OpenCVE Enrichment
EUVD