Impact
This vulnerability is a stored cross‑site scripting flaw that results from improper neutralization of user input during web page generation. An attacker can inject malicious script that will execute in the browser of any visitor to a WooCommerce site using the affected PPOM for WooCommerce plugin. The injected code can steal session cookies, deface the site, or perform other browser‑based attacks. The weakness corresponds to CWE‑79.
Affected Systems
Themeisle PPOM for WooCommerce, versions 33.0.8 and earlier. The issue affects any WordPress site running WooCommerce with this plugin version.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is stored input through the plugin’s add‑on configuration interface, which when processed without proper sanitization, allows an attacker to embed malicious script that will be served to site visitors.
OpenCVE Enrichment
EUVD