Impact
The vulnerability is an improper neutralization of input during web page generation that results in reflected cross‑site scripting. Unescaped user input is echoed back in pages generated by the WooCommerce HTML5 Video plugin, allowing an attacker to inject arbitrary script that executes in the victim’s browser. The weakness is identified as CWE‑79.
Affected Systems
The flaw affects the Webilop WooCommerce HTML5 Video plugin for WordPress, impacting any installation running version 1.7.10 or earlier. Any site that has this plugin enabled and exposes a public or authenticated interface that accepts query parameters will be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. The EPSS score of less than 1 % suggests that, so far, the likelihood of widespread exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed live attacks. Based on the description, the likely attack vector involves delivering a crafted URL or request that contains user‑supplied data rendered unescaped by the plugin; an attacker merely needs to convince a victim to load the page.
OpenCVE Enrichment
EUVD