Impact
This vulnerability arises from the Fast Simon Search, Filters & Merchandising for WooCommerce plugin, where untrusted input is stored and later reflected in generated web pages without proper neutralization. The stored XSS flaw is listed as CWE‑79 and enables an attacker to inject malicious JavaScript that executes in the context of any user who views the compromised page.
Affected Systems
All installations of the Fast Simon Search, Filters & Merchandising for WooCommerce plugin at version 3.0.58 or earlier are affected. The plugin is available for WordPress sites and manages product search, filtering, and merchandising functions.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector would involve a remote attacker injecting malicious data into the plugin’s storage that is subsequently rendered to visitors. No specific exploitation prerequisites are described in the CVE description.
OpenCVE Enrichment
EUVD