Impact
The vulnerability is a stored XSS flaw caused by improper neutralisation of input during web‑page generation within the RealMag777 Active Products Tables for WooCommerce plugin. It permits attackers to embed malicious scripts that are later rendered on pages viewed by site visitors or administrators, potentially enabling arbitrary script execution in the victim’s browser.
Affected Systems
RealMag777 Active Products Tables for WooCommerce is affected for all releases through version 1.0.6.8; newer releases are presumed fixed.
Risk and Exploitability
The CVSS score of 6.5 classifies the problem as moderate, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Attackers can target the plugin by inserting malicious code into any data field handled by the plugin’s admin interface, which is then stored and rendered on public or private pages – this logic is inferred from the description of stored XSS.
OpenCVE Enrichment
EUVD