Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of user input during web page generation in the HasThemes WC Builder plugin. When attackers submit input through the plugin’s fields, malicious script payloads can be stored and later rendered in the browsers of visitors to the site. This allows the injection and execution of arbitrary client‑side code.
Affected Systems
All installations of the WC Builder plugin from HasThemes that are version 1.2.0 or earlier are affected. Any WordPress site that has this plugin deployed and has not upgraded beyond that version may be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 categorizes the issue as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in the CISA KEV catalog. Based on the description, the attacker likely needs access to the WordPress administrative interface or other user roles that can submit data to the plugin in order to inject the malicious payload.
OpenCVE Enrichment