Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce make-email-customizer-for-woocommerce allows Reflected XSS.This issue affects Make Email Customizer for WooCommerce: from n/a through <= 1.0.6.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation in the Make Email Customizer for WooCommerce plugin allows an attacker to inject malicious scripts that are reflected back to the user. This reflected XSS (CWE‑79) can be executed in the victim’s browser, potentially enabling session hijacking, cookie theft, defacement, or phishing. The vulnerability only affects client‑side confidentiality and integrity; the attacker cannot directly alter the server state or data. The impact is limited to users who view pages containing the injected input, but it can be leveraged to compromise any session that relies on the plugin’s output.

Affected Systems

Excellent Dynamics’ WordPress plugin Make Email Customizer for WooCommerce, versions from the initial release through 1.0.6, is affected. The vulnerability exists in all releases up to and including 1.0.6. No specific WordPress core versions are mentioned, so any WordPress installation running the affected plugin version is vulnerable.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high impact. The EPSS score is reported as < 1 %, indicating a low probability that exploit code is actively being used, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through reflected input in URLs or form fields that the plugin renders, and no authentication appears to be required to trigger the script. Because it is client‑side, an attacker can manipulate any user who accesses the vulnerable page, but the attack is limited to the victim’s browser context. Nonetheless, due to the broad reach of WordPress sites and the prevalence of this plugin, the vulnerability remains a significant concern for site administrators.

Generated by OpenCVE AI on April 30, 2026 at 21:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Make Email Customizer for WooCommerce plugin to the latest version (1.0.7 or newer) once the vendor releases a fix.
  • If an update is not yet available, disable or remove the plugin from the site to eliminate the reflected input vectors.
  • Implement a content‑security policy (CSP) that restricts inline scripting and disallows execution of scripts from untrusted sources, and sanitize all plugin output using appropriate escaping functions.
  • Review the site’s output for any other unescaped user content and apply proper input validation and output encoding as a general best practice.

Generated by OpenCVE AI on April 30, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11654 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce allows Reflected XSS. This issue affects Make Email Customizer for WooCommerce: from n/a through 1.0.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce allows Reflected XSS. This issue affects Make Email Customizer for WooCommerce: from n/a through 1.0.5. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce make-email-customizer-for-woocommerce allows Reflected XSS.This issue affects Make Email Customizer for WooCommerce: from n/a through <= 1.0.6.
Title WordPress Make Email Customizer for WooCommerce plugin <= 1.0.5 - Reflected Cross Site Scripting (XSS) vulnerability WordPress Make Email Customizer for WooCommerce plugin <= 1.0.6 - Reflected Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make Email Customizer for WooCommerce allows Reflected XSS. This issue affects Make Email Customizer for WooCommerce: from n/a through 1.0.5.
Title WordPress Make Email Customizer for WooCommerce plugin <= 1.0.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:11:10.303Z

Reserved: 2025-04-09T11:19:28.417Z

Link: CVE-2025-32511

cve-icon Vulnrichment

Updated: 2025-04-17T18:05:23.963Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:40.120

Modified: 2026-04-23T15:29:01.007

Link: CVE-2025-32511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:45:26Z

Weaknesses