Impact
Improper neutralization of input during web page generation (CWE‑79) in the Mollie Payments for WooCommerce plugin allows reflected XSS. A reflected XSS flaw enables malicious scripts to run in a visitor’s browser when a crafted URL is accessed, potentially stealing session cookies, defacing the site, or redirecting to phishing pages. The impact is a classic client‑side attack that can compromise user credentials and manipulate site content without touching server‑side code.
Affected Systems
Mollie Payments for WooCommerce WordPress plugin, versions up to and including 8.1.1. Every installation using the plugin with a version number 8.1.1 or earlier is affected unless patched.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is for an authenticated or unauthenticated user to click a manipulated link or visit a crafted URL that includes the vulnerable parameter; the attacker would then execute arbitrary script in the victim’s browser.
OpenCVE Enrichment