Impact
This vulnerability is a reflected XSS flaw caused by improper input neutralization during web page rendering. An attacker can embed malicious JavaScript in a URL or input that the plugin reflects back in the page. Victims who click the crafted link receive arbitrary script execution within their browser session, which can lead to cookie theft, session hijacking, defacement or other malicious actions.
Affected Systems
The flaw is confined to the Better Customer List for WooCommerce plugin released by Blaze Concepts. Any installation of this plugin through version 1.2.3 or earlier is affected. The vulnerability is listed only for that product line; no other WordPress or WooCommerce components are mentioned as impacted.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. The EPSS score is below 1 %, suggesting that exploitation is unlikely but still possible. It is not yet catalogued in CISA’s KEV. If a user visits a maliciously crafted link with a vulnerable plugin, the exploitation path is straightforward and requires only user interaction. Because the vulnerability is of type reflective XSS, its impact is limited to browsers that load the page; however, any attacker can target thousands of visitors by distributing links, so the risk remains significant for sites that cannot immediately upgrade.
OpenCVE Enrichment
EUVD