Impact
The vulnerability in the Shipment Tracker for Woocommerce plugin version 1.5.3.2 or earlier allows a subscriber to inject arbitrary JavaScript code that is rendered in the browser, potentially enabling session hijacking, phishing, or site defacement. The weakness is a classic form of reflected or stored cross‑site scripting, which falls under CWE‑79. The vulnerability description indicates that user‑supplied data is not properly escaped before being displayed to the subscriber.
Affected Systems
The affected software is the WordPress Shipment Tracker for Woocommerce plugin developed by Amit Mittal. Versions 1.5.3.2 and earlier are vulnerable. The plugin operates within a WordPress installation, rendering its interface and tracking information to logged‑in users and subscribers.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, while an EPSS score of <1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve injection of malicious payloads into subscriber‑facing fields that are later rendered in the browser; a compromised user may be tricked into viewing a shipment page or email that contains the payload. Successful exploitation would allow the attacker to execute arbitrary script with the privileges of the end‑user in their browser.
OpenCVE Enrichment