Impact
Improper neutralization of input during web page generation allows a DOM‑based XSS flaw, meaning an attacker can inject malicious code that runs in the browsers of any user who views the affected page. This code can alter page content or execute arbitrary JavaScript, potentially leading to session hijacking, credential theft, or defacement. The vulnerability is moderate in severity as it requires user interaction to execute the injected script.
Affected Systems
The Advanced Coupons for WooCommerce Coupons plugin, developed by Josh Kohlbach, is affected up to and including version 4.7.1.1. Any WordPress site that installs this plugin within that version range is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate risk level, while the EPSS score of less than 1% indicates a low likelihood of current exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply crafted input that is not properly neutralized; once rendered, any user who visits the affected page will have the injected script executed in their own browser.
OpenCVE Enrichment