Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that are stored by the WP eBay Product Feeds plugin and executed in the browsers of any user who views the affected content, potentially leading to cookie theft, session hijacking, or defacement.
Affected Systems
The vulnerability affects the Rhys Wynne WP eBay Product Feeds WordPress plugin versions from initial release through 3.4.9, which is integrated into WordPress sites that use this product feed plugin.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact, while the EPSS score of less than 1% shows a low likelihood of exploitation in the wild; it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via the plugin’s feed input mechanism, where an attacker can embed JavaScript that is stored and subsequently rendered to other site visitors. No privilege escalation or remote code execution is implied, so the risk is primarily limited to client‑side compromise.
OpenCVE Enrichment