Impact
This vulnerability arises from improper neutralization of user input during web page generation in the Andrew Fisher WOO Codice Fiscale WordPress plugin (CWE‑79). When a request containing crafted data is reflected back to the browser without proper encoding, an attacker can inject and run arbitrary JavaScript in the context of the site. The impact is that injected scripts execute with the visitor’s privileges while they view affected pages.
Affected Systems
The affected product is the Andrew Fisher WOO Codice Fiscale WordPress plugin. All releases from the initial version through and including 1.6.3 are vulnerable. No specific version numbers beyond 1.6.3 were listed.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests a low probability of observed exploitation at the time of this analysis, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted URL or form input that causes the plugin to reflect unsanitized data back to the visitor’s browser; this is an inference based on the nature of reflected XSS and the description of improper input neutralization.
OpenCVE Enrichment
EUVD