Impact
The Order Minimum/Maximum Amount Limits for WooCommerce plugin is vulnerable to stored cross‑site scripting through its settings in all versions up to 4.6.8. The plugin does not properly sanitize or escape user input, allowing an attacker with Shop Manager or higher permissions to inject malicious JavaScript. When a logged‑in or unauthenticated user visits a page that includes the injected script, the code runs in the visitor’s browser under the site’s privileges, enabling credential theft, defacement, or further compromise.
Affected Systems
The vulnerability affects installations of the Order Minimum/Maximum Amount Limits for WooCommerce plugin released by wpcodefactory on WordPress multi‑site environments or sites where the unfiltered_html capability is disabled. All editions of the plugin up to and including version 4.6.8 are impacted.
Risk and Exploitability
The CVSS base score of 4.4 indicates a medium severity flaw, while an EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate as a Shop Manager or a higher role, then use the plugin’s settings interface to submit malicious code. The injected script will execute whenever a visitor loads a page that renders the affected content. The risk is higher for sites that enforce unfiltered_html restrictions on non‑admin roles but still allow Shop Manager actions.
OpenCVE Enrichment