Impact
Improper neutralization of input during web page generation creates a stored cross‑site scripting vulnerability in the Quick View for WooCommerce plugin. An attacker can embed malicious script that will execute in the browsers of anyone who views the affected content, enabling session hijacking, credential theft, defacement, or other client‑side attacks. The weakness is a typical input‑validation flaw identified as CWE‑79.
Affected Systems
The vulnerability affects the Quick View for WooCommerce plugin by ShapedPlugin LLC. All installed versions from the earliest release through 2.2.16 are affected; versions newer than 2.2.16 are not impacted.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity risk. The EPSS score is reported as less than 1 %, suggesting that while exploitation is possible, it is unlikely to be widely seen today. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to provide crafted content that is stored by the plugin—likely through an existing feature that accepts user‑provided data—so the attack vector is local to the plugin but could affect any site that uses it and trusts user input.
OpenCVE Enrichment
EUVD