Impact
The vulnerability is an improper neutralization of input during web page generation that allows a stored XSS flaw in the All Currencies for WooCommerce plugin. An attacker can inject malicious JavaScript that will execute in the browsers of any visitor to the affected WordPress site, potentially compromising user credentials, defacing the site, or facilitating further attacks. The weakness corresponds to CWE‑79.
Affected Systems
The flaw exists in WP Wham All Currencies for WooCommerce plugin versions up through 2.4.3. WordPress sites that have installed this plugin and have not applied the published fix are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation at any given time remains low, and the vulnerability is not in the CISA KEV catalog. While the public description does not detail the required attacker permissions, it is inferred that the attack requires the ability to input data into the plugin’s currency settings or similar fields, which may be limited to administrators or users with content creation rights. Once injected, the script runs in the context of victims visiting affected pages.
OpenCVE Enrichment
EUVD