Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation (Cross‑Site Scripting) that allows an attacker to store malicious scripts in the WordPress plugin’s shipping bar configuration. When visitors load the page, the stored scripts execute in the context of the site, enabling an attacker to alter page content or deface the site. The flaw is classified as CWE‑79.
Affected Systems
The issue affects the WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce plugin for all releases up to and including version 2.4.9. Any WordPress site that installs the plugin at these versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of opportunistic exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely the configuration page or any input that is stored unsanitized by the plugin, which can be accessed by an administrator or other privileged user with write access.
OpenCVE Enrichment