Impact
The WPC Estimated Delivery Date for WooCommerce plugin contains an unsanitized 'rule_data' parameter that allows reflected cross‑site scripting. An attacker can inject JavaScript that runs in a victim’s browser when the victim follows a crafted link or performs an action that includes the malicious parameter. This vulnerability can be abused to steal session data, deface the site, or execute further malicious payloads.
Affected Systems
All WordPress sites running the WPclever WPC Estimated Delivery Date plugin version 4.0.1 or earlier are affected. The issue exists in every released version up to including 4.0.1 of the plugin.
Risk and Exploitability
The CVSS score of 6.1 places the flaw in the medium severity range. EPSS information is not available and the vulnerability is not listed in the KEV catalog, indicating no known widespread exploitation at this time. The attack vector is inferred to be an unauthenticated, social‑engineering approach where the attacker supplies a crafted 'rule_data' value in a link that a victim clicks. The vulnerability requires no privileged access and relies solely on improper input validation, so the attack can be performed from any external address. Although the exploit is relatively simple, it needs a target user to engage with the malicious link, making the overall exploitation probability moderate.
OpenCVE Enrichment