Impact
The vulnerability is a stored cross‑site scripting flaw caused by insufficient input validation when generating web pages. An attacker can insert malicious script code that persists in the plugin data and runs in the browsers of any user who views the affected page. This could lead to session hijacking, cookie theft, defacement, or execution of arbitrary actions on behalf of the user.
Affected Systems
This issue impacts the Woocommerce Line Notify plugin developed by iamapinan, affecting all installations with versions 1.1.7 or earlier. WordPress sites that have loaded the plugin are potentially exposed.
Risk and Exploitability
The CVSS base score of 7.1 indicates a medium to high severity impact. With an EPSS score of less than 1%, the likelihood of widespread exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The stored XSS would typically require an attacker to first compromise an administrator account or exploit the plugin's input interface, after which the malicious payload is served to victim browsers. The attack vector is likely via authenticated access to the plugin's data entry pages.
OpenCVE Enrichment
EUVD