Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pco_58 WC Return products wc-return-product allows Reflected XSS.This issue affects WC Return products: from n/a through <= 1.5.
Published: 2025-10-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a reflected XSS flaw caused by improper input neutralization in the WordPress WC Return products plugin. Attackers can embed malicious scripts into input fields or URLs that the plugin reflects back to the browser, enabling execution of arbitrary JavaScript in the victim’s session. The consequence includes session hijacking, credential theft, defacement, or phishing attempts, affecting the confidentiality and integrity of the user’s session but not directly compromising server credentials or executing code on the server.

Affected Systems

The flaw is present in WordPress WC Return products plugin versions up to and including 1.5. No specific minor versions are listed; all releases from the earliest available to 1.5 are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium‑high severity, yet the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not catalogued in CISA’s KEV list. Attackers would most likely craft a malicious URL containing arbitrary JavaScript, target a user who visits or is tricked into clicking the link, and gain script execution in that user’s browser. The attack requires that the attacker can persuade a user to load the URL or exploit the plugin’s user interface, which is a fairly common scenario for reflected XSS.

Generated by OpenCVE AI on April 29, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WordPress WC Return products plugin to a version newer than 1.5 as released by the vendor
  • Disable or remove the plugin if it is not required for site functionality
  • Implement output encoding or content‑security‑policy headers on the site to mitigate any remaining reflected XSS risk

Generated by OpenCVE AI on April 29, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pco_58 WC Return products wc-return-product allows Reflected XSS.This issue affects WC Return products: from n/a through <= 1.5.
Title WordPress WC Return products plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:18:52.270Z

Reserved: 2025-09-06T04:45:39.391Z

Link: CVE-2025-59004

cve-icon Vulnrichment

Updated: 2025-10-23T13:35:49.196Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T15:15:53.460

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-59004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:30:13Z

Weaknesses