Impact
The vulnerability is an improper neutralization of input during web page generation, identified as a DOM‑based XSS. An attacker could inject malicious JavaScript that will be executed in the context of any visitor to the affected page. This weakness corresponds to CWE‑79 and occurs when the plugin reflects unsanitized data from tag inputs into the page output.
Affected Systems
The issue affects the WordPress WooCommerce Display Products by Tags plugin by Sébastien Dumont for all released versions up to and including 1.0.0. No specific sub‑versions are listed; any installation of this plugin version or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS value of less than 1% suggests a low likelihood of exploitation today. The vulnerability is not included in the CISA KEV catalog. The most likely attack vector involves a crafted request that causes the plugin to echo unescaped tag data into the page, enabling DOM‑based script execution.
OpenCVE Enrichment
EUVD