Impact
An unauthenticated Cross Site Scripting vulnerability exists in MC Woocommerce Wishlist versions up to 1.9.19. The flaw allows an attacker to inject arbitrary JavaScript that will execute in the browsers of any visitor to affected wishlist pages because user input is rendered without proper output encoding. This is a classic XSS flaw corresponding to CWE‑79, which can compromise user credentials, session cookies, or lead to broader phishing attacks.
Affected Systems
The MC Woocommerce Wishlist plugin developed by the Moreconvert team for WordPress sites that have this plugin installed with version 1.9.19 or earlier is vulnerable. The plugin is commonly used in WooCommerce e‑commerce sites to manage wishlists, so e‑commerce sites that rely on this plugin are the primary category of impacted systems.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation. Because authentication is not required, the likely attack vector is via a crafted URL or malicious user input sent to the wishlist interface; when an unauthenticated visitor opens a malicious wishlist link, client‑side attacks could be triggered.
OpenCVE Enrichment