Impact
The vulnerability is an improper neutralization of input that allows a reflected cross‑site scripting (XSS) flaw in the In Stock Mailer for WooCommerce plugin. It enables an attacker to inject malicious JavaScript that executes in the browser of any visitor who accesses a parameter containing the injected payload. The impact can lead to session hijacking, credential theft, or defacement, compromising user data confidentiality, integrity, and availability.
Affected Systems
WordPress installations running Frank’s In Stock Mailer for WooCommerce plugin version 2.1.1 or earlier are affected. No further version granularity is provided, so sites should verify the exact installed version and upgrade if possible.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is considered high severity, but an EPSS score of < 1% indicates low current exploitation probability, and the vulnerability is not listed in CISA KEV. The most likely attack vector is a crafted URL containing malicious input that is reflected in the page output, executed when a target user follows the link. No additional environmental conditions are noted.
OpenCVE Enrichment
EUVD