Impact
The vulnerability is an Improper Neutralization of Script‑Related HTML Tags that allows malicious actors to inject arbitrary JavaScript into the user‑generated review content. This Cross‑Site Scripting flaw means that an attacker could run client‑side code in the context of any visitor’s browser, potentially defacing the site, stealing cookies, or performing other malicious actions.
Affected Systems
WordPress sites using the WooCommerce Photo Reviews plugin from vendor villatheme, version 1.4.4 or earlier are affected. The issue remains in every release up to and including 1.4.4, with no earlier known version identified as affected.
Risk and Exploitability
The CVSS score of 5.3 signals moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would involve a malicious user submitting a review containing a script tag or other injected code, leveraging the fact that the plugin does not sanitize user input before rendering it.
OpenCVE Enrichment