Impact
The Product Catalog Simple plugin is vulnerable to cross‑site scripting because user input is not properly neutralized before being stored and later rendered in web pages. An attacker can inject malicious scripts that will execute whenever a catalog entry is displayed, potentially stealing session cookies, defacing content, or executing further malicious actions. This stored XSS is a classic input validation flaw that directly exposes users to code execution in their own browsers.
Affected Systems
The flaw affects all installations of impleCode’s Product Catalog Simple plugin that are version 1.8.1 or older. The affected product is available as a WordPress post‑type‑x plugin, and any site that still uses a vulnerable version is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% means the likelihood of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. However, if an attacker can craft a catalog entry that contains malicious script, the stored XSS will trigger in every user who views that entry, making it potentially impactful if the site attracts many visitors. The exploit requires only the ability to add or edit catalog items, which is typically available to site administrators or privileged users.
OpenCVE Enrichment
EUVD