Impact
The Deliver via Shipos for WooCommerce plugin contains an improper neutralization of input during web page generation, resulting in a reflected cross‑site scripting vulnerability. An attacker can supply crafted input that is reflected in the browser without proper escaping, enabling the execution of malicious code in the victim’s session. The impact includes theft of session cookies, defacement of the site, or execution of further attacks from the victim’s browser. This weakness is categorized as CWE‑79.
Affected Systems
Vulnerable systems are WordPress sites that use the Deliver via Shipos for WooCommerce plugin version 2.1.7 or earlier, developed by Matat Technologies.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. An EPSS score of less than 1% suggests that exploitation in the wild is infrequent, and the bug is not listed in the CISA KEV catalog. Exploitation requires an attacker to trick a user into visiting a crafted URL or form input, typically through phishing or compromised content. The attacker need not gain privileged access, so the risk is primarily user‑centric.
OpenCVE Enrichment
EUVD