Impact
The flaw is a CSRF vulnerability that permits an attacker to induce an authenticated user to submit a request that writes malicious script to the plugin’s storage, resulting in stored cross‑site scripting. Because the stored script is permanently embedded in the site, any visitor who loads the affected page will run the attacker's code in their browser. The weakness is classified as CWE‑352, a classic CSRF flaw.
Affected Systems
This vulnerability affects the GST for WooCommerce plugin by Ashwani Kumar, versions up to and including 2.0. Any site running one of these versions without the fix is susceptible.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, yet the EPSS score is below 1 %, implying a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to lure a legitimate user to a crafted URL or form that triggers the vulnerable action; the attack does not require elevated privileges on the target system, making it relatively easy to exploit if a suitable social engineering vector exists.
OpenCVE Enrichment
EUVD