Impact
An improper neutralization of user input in the Ala Falaki a Gateway for Pasargad Bank on WooCommerce plugin enables reflected cross‑site scripting. The vulnerability allows an attacker to embed malicious scripts that are executed in the browsers of users who view the affected page, potentially compromising the confidentiality and integrity of user data and the session state of the site.
Affected Systems
The vulnerability affects installations of Ala Falaki a Gateway for Pasargad Bank on WooCommerce that are at or below version 2.5.2.
Risk and Exploitability
With a CVSS score of 7.1 the issue is considered moderate in severity. The EPSS score of less than 1 % indicates a very low probability of exploitation at the current time, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need only the ability to send crafted input to the WooCommerce front‑end, so the attack vector is likely a malicious link or form submission that the victim clicks in a web browser. Because it is an XSS flaw, damages such as session hijacking, defacement, or phishing can be achieved if the victim accepts the malicious content.
OpenCVE Enrichment
EUVD