Impact
The vulnerability is an improper neutralization of input during web page generation, classified as a stored XSS flaw. Malicious code injected via the plugin’s configuration pages is saved to the database and subsequently rendered in output pages, which can lead to client‑side script execution, defacement, or session hijacking. The weakness is identified as CWE‑79 and provides a medium level of impact on confidentiality, integrity, and availability for users who view affected pages.
Affected Systems
The issue affects the WordPress plugin Maximum Products per User for WooCommerce from its initial release through version 4.4.3, as distributed by WPFactory.
Risk and Exploitability
The CVSS score of 6.5 indicates a substantial risk level. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires access to the WordPress admin area where an attacker can input malicious script into product‑limit fields; once stored, the payload is reflected to all site visitors.
OpenCVE Enrichment