Impact
The WooCommerce Placetopay Gateway plugin for WordPress contains a flaw that permits an attacker to supply an unsanitised 'redirect-url' parameter. When the value of this parameter is reflected in page content without proper escaping, arbitrary JavaScript can be executed in the victim’s browser. This vulnerability is a typical example of Reflected XSS and can be leveraged by unauthenticated attackers to compromise user accounts or exfiltrate sensitive data recorded in the browser session. The vulnerability is tied to CWE‑79, indicating insufficient output encoding for user input.
Affected Systems
All installations of the Evertec WooCommerce Placetopay Gateway plugin version 3.2.2 or earlier are affected, including the Belize, Colombia, Ecuador, Honduras, and Uruguay variants. Any WordPress site that has installed one of these plugins without applying the later patch is at risk.
Risk and Exploitability
The CVSS score of 6.1 denotes a moderate severity. The EPSS score of less than 1% indicates a low current likelihood of exploitation, but the fact that it can be triggered via a crafted link to a third‑party site means that an attacker can lure unsuspecting users to execute malicious scripts. The vulnerability does not require authentication, making it broadly exploitable. As the attack occurs in the victim’s browser, the impact includes disclosure of session cookies and potential credential theft, but it does not directly allow server‑side compromise.
OpenCVE Enrichment