Impact
The Revamp CRM for WooCommerce plugin contains a reflected XSS flaw where user input passed to a page is not properly escaped. An attacker can inject malicious JavaScript that executes in the context of a victim’s browser, allowing cookie theft, session hijacking, defacement or redirection. The weakness is a classic input‑validation problem (CWE‑79).
Affected Systems
Affected: Revamp CRM for WooCommerce plugin version 1.1.2 and earlier. The plugin is available for WordPress sites using WooCommerce.
Risk and Exploitability
The likely attack vector is a malicious URL injected by an attacker that the user eventually visits. Because the vulnerability is client‑side and relies on user interaction, the threat model typically involves phishing or social‑engineering campaigns. The CVSS score of 7.1 indicates high severity, the EPSS score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV, but administrators should treat it as a high‑priority issue.
OpenCVE Enrichment
EUVD