Impact
This vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of user input during web page generation in the Membership For WooCommerce plugin. An attacker can inject malicious scripts that will execute in the browsers of visitors who view affected pages, potentially enabling cookie theft, session hijacking, defacement, or the execution of arbitrary code within the context of the site.
Affected Systems
The flaw affects the WP Swings Membership For WooCommerce plugin on all WordPress sites that use any version from the earliest release through 2.8.0. The vulnerability is present in every release up to and including version 2.8.0.
Risk and Exploitability
The assigned CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would require a browser that renders the vulnerable page and would need to supply crafted input – for example via URL parameters or form fields – to trigger the DOM manipulation. Given its moderate score, the potential impact is significant but the low exploitation probability reduces overall risk for organizations that maintain up‑to‑date plugins.
OpenCVE Enrichment
EUVD