Impact
Improper neutralization of user input during web page generation allows an attacker to inject arbitrary client‑side script. The Pesapal Gateway for Woocommerce plugin reflects unsanitized request parameters back to the browser, enabling a Reflected XSS flaw. When a victim clicks a crafted link that includes malicious code, the script runs in the victim’s browser and can steal cookies, session tokens, or perform actions on behalf of the user.
Affected Systems
This vulnerability affects Jakeii’s Pesapal Gateway for Woocommerce plugin for WordPress. Any installation of the plugin with a version number less than or equal to 2.1.0 is vulnerable because the flaw exists in all releases prior to 2.1.1.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as High severity. An EPSS score of less than 1 % indicates a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is simple: a malicious link containing a forged query parameter is presented to a user; once the user clicks the link, the malicious script executes in the victim’s browser, potentially compromising session integrity or other client‑side data.
OpenCVE Enrichment
EUVD