Impact
The Vidish Combo Offers WooCommerce plugin contains an improper neutralization of input during web page generation that enables DOM‑based cross‑site scripting. This flaw allows an attacker to inject malicious script into the HTML delivered to a victim’s browser, potentially enabling client‑side code execution. The weakness resides in inadequate input validation and sanitization, identified as CWE‑79.
Affected Systems
WordPress sites that have the Combo Offers WooCommerce plugin version 4.2 or earlier are vulnerable. The issue is independent of the WordPress core version, as it arises from the plugin’s handling of user‑controlled data.
Risk and Exploitability
The CVSS score of 6.5 categorizes this as a medium‑severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation based on current observable activity. The vulnerability is not listed in CISA’s KEV catalog, indicating no known wide‑scale exploitation. The DOM‑based nature of the flaw implies it can be triggered by a user interacting with a vulnerable page, possibly through a crafted link or form input; authentication is not mentioned in the CVE data, so no assumption about required privileges is made.
OpenCVE Enrichment