Impact
The Woocommerce Notify Updated Product plugin through version 1.6 contains a Cross‑Site Request Forgery flaw that allows an attacker to inject malicious JavaScript into the site’s interface. This vulnerability is a classic example of CWE-352 and can enable stored cross‑site scripting when a forged request is accepted by the plugin’s processing code.
Affected Systems
Sites running the ablancodev WooCommerce Notify Updated Product plugin from any release up to and including 1.6 are affected. No other product versions or vendors are listed as impacted.
Risk and Exploitability
The flaw carries a CVSS score of 6.5 and an EPSS score of less than 1 percent, indicating a moderate severity and low projected exploitation frequency. It is not listed in the CISA KEV catalog. The attack vector is inferred to be cross‑site request forgery, so the attacker must target a user who is logged in and has permission to use the plugin’s functionality. With that foothold, the attacker can insert payloads that are subsequently rendered and persisted by the plugin’s storage logic.
OpenCVE Enrichment
EUVD