Impact
This vulnerability is an unauthenticated reflected cross‑site scripting flaw in the WordPress SureCart plugin versions 4.3.2 and earlier. An attacker can inject malicious JavaScript through user‑controlled input that the plugin outputs without proper encoding, allowing arbitrary script execution in the victim’s browser. The vulnerability is identified as CWE‑79. The CVE description does not detail specific exploitation scenarios beyond the XSS capability.
Affected Systems
SureCart, a plugin for WordPress, is affected in all released versions up to and including 4.3.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw, and because authentication is not required, any web visitor can trigger it, making it broadly exploitable. EPSS score is not available, so a current exploit probability could not be quantified. The vulnerability is not listed in the CISA KEV catalog. An attacker can reach the flaw by crafting a malicious URL or form input that the plugin reflects back to the user; once the code executes, it runs with the site’s domain context and could manipulate the page or exfiltrate data.
OpenCVE Enrichment