Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud cart66-cloud allows Reflected XSS.This issue affects Cart66 Cloud: from n/a through <= 2.3.7.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

It is a reflected XSS flaw caused by improper neutralization of user input in the Cart66 Cloud plugin. An attacker can craft a URL containing malicious script that is returned unescaped in the page response, allowing execution in the browsers of anyone who follows the link. This can lead to cookie theft, credential hijacking or the injection of arbitrary webpage content.

Affected Systems

The flaw exists in Lee Blue’s Cart66 Cloud WordPress plug‑in versions up to and including 2.3.7. WordPress sites that have installed this plug‑in without updating are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score of < 1 % suggests that, at present, exploitation is unlikely but not impossible. The flaw is client‑side, so any visitor who follows a crafted link can be impacted, giving the attacker the ability to compromise user sessions or deface the site. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit evidence has been reported.

Generated by OpenCVE AI on April 30, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cart66 Cloud plug‑in to any release newer than 2.3.7.
  • If an upgrade is not currently possible, remove the plug‑in or disable all user‑controllable input fields until a patched version is available.
  • Review and ensure that any input handled by the plug‑in is properly sanitized before rendering on the page.

Generated by OpenCVE AI on April 30, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11725 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud cart66-cloud allows Reflected XSS.This issue affects Cart66 Cloud: from n/a through <= 2.3.7.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.
Title WordPress Cart66 Cloud Plugin <= 2.3.7 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:26.357Z

Reserved: 2025-04-09T11:21:04.031Z

Link: CVE-2025-32653

cve-icon Vulnrichment

Updated: 2025-04-17T18:08:37.824Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:49.427

Modified: 2026-04-23T15:29:17.273

Link: CVE-2025-32653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:15:16Z

Weaknesses