Impact
The Advanced Customized Prompts WordPress plugin through version 1.0.1 allows any authenticated user such as a subscriber to inject JavaScript into the product popup configuration without performing a capability check or escaping the stored values. When an affected product is viewed by visitors, the injected script executes in the visitor’s browser, enabling attackers to steal session cookies, deface the site, or perform other malicious actions against customers. This vulnerability is a classic stored cross‑site scripting flaw.
Affected Systems
WordPress installations that have the Advanced Customized Prompts plugin of version 1.0.1 or earlier installed are affected. The issue occurs when an authorized subscriber creates or edits a product popup configuration using that plugin.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, but the high impact of stored XSS indicates that exploitation is feasible once an authenticated user has access to the plugin’s configuration interface. An attacker who can log into the site as a subscriber can store malicious JavaScript that is then executed automatically for any visitor viewing the product, making the attack vector an authenticated exploitation of the WordPress back‑end followed by cross‑site scripting on the front‑end. The CVSS score is not provided, but the severity can be considered high due to the potential for widespread browser compromise.
OpenCVE Enrichment