Impact
Improper neutralization of input during web page generation in the ILLID Advanced Woo Labels plugin allows stored cross‑site scripting. An attacker who can inject arbitrary script into label data can have that script executed in the browsers of anyone who views the affected page.
Affected Systems
The vulnerability affects the WordPress Advanced Woo Labels plugin from its initial release through version 2.15. Users deploying any version of this plugin prior to the disclosed fix are at risk. The problem resides in the plugin’s handling of label input fields.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation involves injecting malicious script into label data, which is stored and served to visitors of affected pages. The attack vector is likely through the plugin’s label creation or editing interface, although specific details are not provided in the CVE description.
OpenCVE Enrichment
EUVD