Impact
The rextheme Product Feed Manager For WooCommerce plugin is vulnerable because the "s" search parameter is not properly sanitized or escaped. This flaw allows an unauthenticated attacker to embed JavaScript that is reflected back into the returned page. When a victim’s browser renders the maliciously crafted URL, the injected script executes in the context of the admin or frontend page. The weakness is classified as CWE‑79.
Affected Systems
All installations of the rextheme:Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress up to and including version 7.6.1 are affected, regardless of the underlying WordPress core version.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation in the wild is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an attacker can craft a URL containing a malicious value for the "s" parameter and entice a user to click it. If successful, the victim’s browser will execute the injected script.
OpenCVE Enrichment