Impact
Improper neutralization of input during page generation allows attackers to inject arbitrary script that is stored within the Additional Custom Product Tabs for WooCommerce plugin. The resulting stored XSS can cause client‑side code to execute in the browsers of any user who views affected product tabs, potentially leading to session hijacking, credential theft, or defacement. The weakness is a classic input validation flaw, classified as CWE‑79.
Affected Systems
The vulnerability affects the WPFactory Additional Custom Product Tabs for WooCommerce plugin for WordPress. All installations running versions not newer than 1.7.3 are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% shows a very low likelihood of exploitation in the near term, and the CVE is not listed in the CISA KEV catalog. Attackers would need to input malicious data through the plugin’s admin interface or any input field that the plugin exposes, and all visitors to the affected product pages would receive the injected script. The attack vector is stored cross‑site scripting rather than remote code execution.
OpenCVE Enrichment
EUVD