Impact
The vulnerability is an improper neutralization of input during web page generation that allows attackers to inject malicious scripts via reflected XSS. The injected code can execute in the context of logged‑in users, potentially compromising session cookies, authorizing malicious requests, or defacing site content. The impact is a breach of confidentiality and integrity of user data and possible hijacking of authenticated sessions.
Affected Systems
All installations of the WordPress plugin FluentCart by WPManageNinja with a version less than 1.3.0 are affected. The vulnerability applies to every release in that series up to but not including 1.3.0 on WordPress sites that load the plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests low but non‑zero exploitation probability at the time of reporting, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the reflected XSS by sending crafted input to the plugin, usually via query parameters or form submissions, and the required conditions are minimal as the vulnerable input is not properly sanitized before rendering. No prerequisites beyond reaching an affected endpoint are indicated by the description.
OpenCVE Enrichment