Impact
The vulnerability in the RealMag777 Active Products Tables for WooCommerce plugin (versions <=1.0.7) is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of user input during page rendering. An attacker can inject malicious JavaScript into the content generated by the plugin, potentially affecting the confidentiality, integrity or availability of the site for visitors. This weakness is identified as CWE‑79.
Affected Systems
Affected vendor: RealMag777. Product: Active Products Tables for WooCommerce. All installer releases from the earliest versions through version 1.0.7 contain the flaw; no more specific versioning is disclosed.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread active exploits. Based on the description of DOM‑based XSS, the likely attack vector is via client‑side interaction with the plugin’s interface, typically by supplying crafted input that is reflected in the page, and it does not require authentication. Overall risk is moderate with a low likelihood of exploitation.
OpenCVE Enrichment