Impact
This vulnerability arises from improper neutralization of user input that is reflected back in the web page, allowing arbitrary JavaScript execution when a crafted request is visited. The injected script can steal user credentials, deface the site, or redirect to malicious URLs, effectively compromising confidentiality, integrity, and availability for affected users.
Affected Systems
Any WordPress installation that has the WooCommerce Sales MIS Report plugin from infosoftplugin with a version up to and including 4.0.3 is affected. The vulnerability is present in every release from the earliest version through 4.0.3.
Risk and Exploitability
The CVSS severity of 7.1 classifies it as high risk. The EPSS score of less than 1% suggests that exploitation is currently rare, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a remote web request that contains malicious input, and the exploit requires a victim user to visit a crafted URL. While the probability of indiscriminate exploitation is low, the impact of a successful attack is significant.
OpenCVE Enrichment
EUVD