Impact
This vulnerability arises from improper neutralization of input during web page generation in the SysBasics Customize My Account for WooCommerce WordPress plugin. The flaw allows a malicious string to be reflected in the browser without proper escaping, enabling an attacker to inject arbitrary JavaScript. If executed, the injected script runs in the context of the user’s browser session, potentially compromising data, session cookies, or facilitating further attacks such as phishing or credential theft.
Affected Systems
WordPress sites that use the SysBasics Customize My Account for WooCommerce plugin on versions up to and including 2.8.22 are affected. The issue applies to all users who can load pages that include the unescaped input from this plugin, including visitors of publicly accessible e‑commerce sites that use WooCommerce.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely be achieved by an attacker inserting a crafted query parameter or form value that the plugin reflects back to the user’s browser. Successful exploitation requires the victim to visit a malicious URL or submit a crafted request; therefore, it is a user‑interaction dependent attack vector.
OpenCVE Enrichment
EUVD