Impact
An Improper Control of Generation of Code (CWE-94) vulnerability exists in the WordPress Advanced Woo Labels plugin that allows Remote Code Inclusion. The vulnerability can enable an attacker to inject and execute arbitrary code on the server hosting the WordPress site. Based on the description, it is inferred that an attacker could gain full control over the affected site, enabling actions such as data exfiltration or defacement. Key detail from vendor description: "allows Remote Code Inclusion."
Affected Systems
All releases of Advanced Woo Labels up to and including version 2.36 are affected. The vendor identified the issue as present from the initial release through <= 2.36.
Risk and Exploitability
The CVSS base score of 7.2 indicates medium‑high severity, while the EPSS score of less than 1 % suggests a low exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network, requiring an attacker to send crafted HTTP requests to the plugin’s endpoints while the WordPress site is online, as inferred from the phrase "Remote Code Inclusion" and the plugin’s web application context.
OpenCVE Enrichment