Impact
The vulnerability is a reflected cross‑site scripting flaw that allows attackers to inject malicious JavaScript into the web pages rendered by the WooCommerce TBC Credit Card Payment Gateway (Free) plugin. When the plugin processes unsanitized user input, an attacker can craft a URL that injects script code; upon redirect to a legitimate site, the code executes with the privileges of the visiting user. This flaw can result in session hijacking, credential theft, or defacement, compromising confidentiality, integrity, and availability on a per‑user basis.
Affected Systems
The flaw affects the WooCommerce TBC Credit Card Payment Gateway (Free) plugin released by We Are De, for all versions up to and including 2.0.0. Users running these versions should verify the installed plugin version and determine whether a patch or newer release is available.
Risk and Exploitability
The CVSS score of 7.1 marks this issue as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need to lure or trick a legitimate user to visit a crafted URL. Without additional access controls, the risk is limited to the specific visitor’s session, but widespread phishing could amplify impact.
OpenCVE Enrichment
EUVD