Impact
Improper neutralization of input during web page generation in WordPress Booster for WooCommerce creates a reflected XSS flaw. When an attacker supplies crafted data that is echoed back without adequate escaping, JavaScript can run with the victim’s privileges, potentially harvesting credentials or hijacking sessions. This weakness is identified as a CWE‑79 type vulnerability.
Affected Systems
The issue affects the Pluggabl Booster for WooCommerce plugin for WordPress, versions 7.2.5 and any earlier releases. No other products or vendors are mentioned as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 classifies the vulnerability as high severity. The EPSS score of < 1% indicates a low but non‑zero likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to entice a user to open a malicious URL or crafted link; once the reflected payload executes in the user’s browser, it can perform actions on behalf of the user within the site.
OpenCVE Enrichment