Impact
The vulnerability is a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping of the 'style' attribute in the Brands for WooCommerce shortcode. Authenticated users with contributor‑level permissions or higher can supply malicious script code that is persisted in the WordPress database. When other users navigate to a page that includes the affected shortcode, the injected script executes in their browser.
Affected Systems
WordPress sites that install the Berocket Brands for WooCommerce plugin version 3.8.8 or earlier are impacted. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderately high severity, while the EPSS score of less than 1% points to a low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must first obtain authenticated access at the contributor level or higher on the target WordPress site; no remote, unauthenticated exploitation is possible.
OpenCVE Enrichment