Impact
The vulnerability is a cross‑site request forgery flaw that allows an attacker to inject persistent JavaScript into the target system. Because the attack leverages a stored XSS payload, an attacker could run arbitrary scripts in the browser context of any user who views the affected content, leading to session hijacking, credential theft, or defacement of the site.
Affected Systems
WordPress sites using thethemelocation "Change Cart button Colors WooCommerce" plugin version 1.0 or older are affected. No other vendor or product versions are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web request that bypasses the plugin’s CSRF defenses; an attacker can create a link or form that, when clicked by an authenticated administrator, stores malicious JavaScript code in the site’s storage. Once stored, the script runs for all subsequent visitors, providing enduring access to the site and its users.
OpenCVE Enrichment
EUVD