Impact
The vulnerability is an Open Redirect flaw (CWE‑601) in the Facebook for WooCommerce WordPress plugin. An attacker can manipulate the redirect URL parameter so that users are sent to an untrusted website. This can be used to facilitate phishing campaigns, leading to credential compromise, loss of confidentiality, and potential downstream exploitation.
Affected Systems
WordPress sites that use the Facebook for WooCommerce plugin version 3.7.0 or earlier are affected. The flaw is present in all prior releases up to and including 3.7.0. Sites running any of those plugin versions are at risk.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate impact. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting limited publicly known exploitation. The attack requires a user to be redirected, so the likely vector is a crafted link or infected content within the WooCommerce storefront. The vulnerability can be triggered without authentication, making it accessible to unauthenticated users. The risk remains moderate, but when combined with social engineering, it poses a realistic phishing threat.
OpenCVE Enrichment