Impact
A stored cross‑site scripting flaw in WPFactory Wishlist for WooCommerce allows an attacker to inject malicious script code that will execute in the browser of any user who views a compromised wishlist. The injected script can hijack a user’s session, deface the site, or perform arbitrary actions as that user, thereby affecting the confidentiality, integrity, and availability of user sessions and site content.
Affected Systems
The vulnerability affects the WPFactory Wishlist for WooCommerce plugin, versions up to and including 3.2.2. No other products or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of fewer than 1% shows that the likelihood of exploitation is low at present. The plugin is not listed in the CISA KEV catalog. Exploitation generally requires the attacker to be able to add or edit wishlist items that will be stored and later rendered without proper escaping, and the malicious payload will be triggered when another user views the affected wishlist.
OpenCVE Enrichment
EUVD