Impact
The vulnerability allows an attacker to exploit a missing cross‑site request forgery protection to inject a malicious script that is stored in the plugin’s data store. Once stored, the script will execute whenever an administrator or any user views the affected content, potentially enabling session hijacking, defacement, or other malicious actions as described by the Identified CWE-352.
Affected Systems
Any WordPress site using Anton Bond’s Additional Order Filters for WooCommerce plugin version 1.22 or earlier is susceptible. No additional version granularity is disclosed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑impact vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the issue is not listed in CISA’s KEV catalog. Exploitation requires an attacker to coerce a legitimate user into submitting a crafted request, after which the stored script will run with the victim’s privileges. The risk is elevated for sites that rely heavily on this plugin and for administrators who use the same credentials across sites.
OpenCVE Enrichment
EUVD