Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, enabling a reflected Cross‑Site Scripting (XSS) flaw. Unescaped user supplied data can be embedded directly into a web page, permitting an attacker to inject JavaScript that runs in the victim’s browser. Such script execution can lead to session hijacking, credential theft, or redirection to malicious sites. The weakness is identified as CWE‑79.
Affected Systems
The affected component is the CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce plugin for WordPress. All plugin versions from the first released version through 1.7.6 are impacted. Users who have not updated beyond 1.7.6 are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog, implying no confirmed public exploits. The most likely attack vector is a remote, web‑based request to a page that processes user input, such as a crafted URL or form submission. Attackers can trigger the vulnerability from anywhere with access to the site, but success requires some exposure to user‑directed input rendering.
OpenCVE Enrichment
EUVD