Impact
The Goracash WordPress plugin contains a stored cross‑site scripting flaw due to improper neutralization of user input during web page generation. An attacker can supply malicious script payloads that are preserved in the site's database and later rendered in the browser, potentially executing arbitrary code in the context of anyone viewing the affected page.
Affected Systems
WordPress sites that have installed the Davaxi Goracash plugin version 1.1 or earlier. The vulnerability applies to all supported releases of the plugin up to and including 1.1, regardless of the WordPress core version. Sites that rely on Goracash for payment or shopping cart functionalities are included.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need access to a content or payment entry point that accepts user‑controlled data, and the poisoning of that data would result in a stored XSS scenario impacting subsequent site visitors. This scenario is inferred from the stored XSS nature of the flaw since the description does not specify the exact entry point.
OpenCVE Enrichment
EUVD