Impact
It is a reflected XSS flaw caused by improper neutralization of user input in the Cart66 Cloud plugin. An attacker can craft a URL containing malicious script that is returned unescaped in the page response, allowing execution in the browsers of anyone who follows the link. This can lead to cookie theft, credential hijacking or the injection of arbitrary webpage content.
Affected Systems
The flaw exists in Lee Blue’s Cart66 Cloud WordPress plug‑in versions up to and including 2.3.7. WordPress sites that have installed this plug‑in without updating are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score of < 1 % suggests that, at present, exploitation is unlikely but not impossible. The flaw is client‑side, so any visitor who follows a crafted link can be impacted, giving the attacker the ability to compromise user sessions or deface the site. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit evidence has been reported.
OpenCVE Enrichment
EUVD