Impact
The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin allows stored XSS through the untrusted 'row_type' parameter. This flaw is rooted in insufficient input validation and improper output encoding, making it a CWE‑79 vulnerability. An attacker with shop manager‑level or higher permissions can inject scripts that execute in the context of any user who visits the affected page, enabling cookie theft, credential capture, or defacement.
Affected Systems
The vulnerability affects the WordPress plugin SysBasics Customize My Account for WooCommerce – Live My Account Customizer released by vendor phppoet in all releases up to and including version 4.4.14. Any WordPress installation that has this plugin installed and has users with shop manager or higher roles is in scope.
Risk and Exploitability
The posted CVSS score of 4.4 places this vulnerability in the moderate range. The EPSS score is less than 1 %, indicating a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access with at least shop manager privileges, and the attacker would need to submit malicious data via the configuration interface that stores the payload for later rendering to end users.
OpenCVE Enrichment