Impact
Improper neutralization of input during web page generation in the embed‑rentle component of the Twice Commerce plugin allows an attacker to inject arbitrary scripts into browsers that view affected pages. The vulnerability is a DOM‑based XSS flaw classified as CWE‑79 and carries a CVSS score of 6.5, indicating a moderate severity if exploited.
Affected Systems
The flaw affects the Twice Commerce WordPress plugin, specifically the embed‑rentle feature, in all versions from the earliest release through 1.3.1. Any WordPress site that has installed or updated the plugin to a version no higher than 1.3.1 is potentially vulnerable, regardless of other configuration settings.
Risk and Exploitability
The EPSS score of less than 1 % shows a low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 6.5 highlights moderate severity. Exploitation requires supplying malicious input that is reflected into the page for any user who accesses the affected embed‑rentle page.
OpenCVE Enrichment
EUVD