Impact
The flaw in the Payphone WooCommerce – Payphone Gateway plugin results from improper neutralization of user input during web page generation. Unsanitized data is reflected back to visitors, enabling the injection and execution of arbitrary JavaScript in their browsers. The vulnerability is categorized as a reflected cross‑site scripting (CWE‑79) attack.
Affected Systems
All WordPress sites that have the Payphone WooCommerce – Payphone Gateway plugin installed in versions up to and including 3.2.0 are affected. The flaw is present across all versions released before 3.2.1, regardless of the WordPress core version. Users of later releases (i.e., any release newer than 3.2.0) are not impacted unless they reinstall an older version.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity potential impact, while the EPSS score of less than 1% indicates a very low current probability of exploitation. The vulnerability is not recorded in the CISA KEV catalog. Exploitation requires an attacker to present a crafted URL or link to a site visitor, thereby causing the stored string to be rendered in the victim’s browser and executed as code.
OpenCVE Enrichment
EUVD