Impact
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digireturn DN Shipping by Weight for WooCommerce allows Reflected XSS. This flaw permits an attacker to inject malicious scripts that are executed in the context of the affected site, potentially hijacking user sessions or manipulating page content.
Affected Systems
digireturn DN Shipping by Weight for WooCommerce (WordPress plugin) – versions <= 1.2. Users running the plugin on any WordPress installation are vulnerable; newer releases starting at 1.3 are not affected.
Risk and Exploitability
The CVSS score of 7.1 marks this flaw as high severity, but the EPSS score of < 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers likely need to craft a URL or input that the plugin reflects in a browser output, a typical path for reflected XSS, and do not require elevated privileges or server access.
OpenCVE Enrichment
EUVD