Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can inject arbitrary JavaScript into the output of the WooCommerce Vehicle Parts Finder plugin because user‑supplied input is not properly neutralized. The reflected XSS flaw allows malicious code to run in the browser of any user who views the affected page, potentially leading to credential theft, session hijacking, or defacement. This weakness corresponds to CWE‑79.

Affected Systems

All sites running wpinstinct’s WooCommerce Vehicle Parts Finder plugin with versions 3.7 or earlier are susceptible. The vulnerability affects the plugin from the earliest available build up through 3.7, meaning that any installation of the plugin that has not been upgraded to a later version is at risk.

Risk and Exploitability

The CVSS base score of 7.1 indicates moderate to high severity, but the EPSS score of <1% suggests a low current exploitation probability. The flaw is not listed in the CISA KEV catalog, and it is remote and does not require authentication; an attacker only needs to lure a victim to a crafted URL containing malicious query parameters. Consequently, while the potential impact is significant, the likelihood of widespread exploitation is presently low, but should not be ignored.

Generated by OpenCVE AI on April 29, 2026 at 16:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WooCommerce Vehicle Parts Finder plugin to at least version 3.8, if available, or the latest release that contains the fix.
  • In the meantime, block or filter suspicious requests that include script tags or encoded JavaScript payloads in query parameters by configuring a web application firewall or using a security plugin that applies input sanitization.
  • Verify that the plugin properly sanitizes and escapes all user‑supplied data before rendering it. If not, implement server‑side validation on the affected fields or apply WordPress functions such as esc_html or wp_kses to safely encode output.

Generated by OpenCVE AI on April 29, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Wpinstinct
Wpinstinct woo Commerce Vehicle Parts Finder
Vendors & Products Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Wpinstinct
Wpinstinct woo Commerce Vehicle Parts Finder

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.
Title WordPress WooCommerce Vehicle Parts Finder plugin <= 3.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Woocommerce Woocommerce
Wordpress Wordpress
Wpinstinct Woo Commerce Vehicle Parts Finder
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:24:10.805Z

Reserved: 2025-06-11T16:06:50.724Z

Link: CVE-2025-49911

cve-icon Vulnrichment

Updated: 2025-10-23T13:46:09.746Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:37.043

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-49911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:00:13Z

Weaknesses