Impact
The SysBasics Customize My Account for WooCommerce plugin is vulnerable to reflected cross‑site scripting through the unvalidated 'tab' parameter in the plugin_options_page() rendering within the WordPress admin dashboard. Unauthenticated attackers can craft a link that includes a malicious 'tab' value, causing arbitrary JavaScript to be reflected and executed when a logged‑in Shop Manager or higher user clicks it. The flaw stems from insufficient input sanitization and output escaping.
Affected Systems
All installed instances of the SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin up to and including version 4.3.6, distributed by the phppoet vendor. The vulnerability impacts WordPress sites that use WooCommerce for e‑commerce, specifically when the plugin’s admin options page is accessible to users with Shop Manager‑level or higher privileges.
Risk and Exploitability
With a CVSS score of 6.1 the vulnerability is rated moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at the time of assessment. The flaw is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering component—an attacker must convince an authorized admin to click a crafted link—making the attack vector remote but requiring a targeted privileged user. Consequently, while the impact could allow arbitrary script execution within the admin context, the overall risk remains contingent on access control and user awareness.
OpenCVE Enrichment