Impact
The vulnerability is a stored XSS flaw caused by improper neutralization of input during web page generation in the WPFactory Product Notes Tab & Private Admin Notes for WooCommerce plugin. An attacker who can insert or edit notes can embed malicious script that will run in the browsers of any user who views the note. This could compromise the privacy or integrity of the viewing user’s session, and the script runs with the privileges of that user. Based on the description, it is inferred that the attacker could potentially hijack sessions, deface the site, or execute other malicious actions in the victim’s browser.
Affected Systems
WordPress sites running WPFactory’s Product Notes Tab & Private Admin Notes for WooCommerce plugin with any version up to and including 3.1.0. Users who have permission to create or edit product notes—typically administrators or staff with note‑creation rights—can inject the malicious payload.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity issue, and the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An authenticated attacker with note‑creation privileges is the likely attack vector; once the payload is stored, any user who opens the note will have the script executed in their browser.
OpenCVE Enrichment
EUVD