Impact
The 17TRACK for WooCommerce plugin contains a reflected cross‑site scripting flaw due to improper input neutralization during web page generation. This flaw allows an attacker to craft a URL or form input containing malicious JavaScript that the plugin reflects back to the victim’s browser. The vulnerability enables execution of arbitrary client‑side code with the privileges of the affected site, which could be used for defacement or phishing actions in the user’s browser.
Affected Systems
WordPress installations that include the 17TRACK for WooCommerce plugin version 1.2.10 or earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a typical reflected XSS via HTTP requests to the plugin’s front‑end endpoints, requiring a victim to follow a crafted URL or submit a malicious form.
OpenCVE Enrichment
EUVD