Impact
The WordPress eCommerce Product Catalog plugin contains an unauthenticated Cross Site Scripting (XSS) vulnerability in all versions up to and including 3.5.4. The flaw allows malicious scripts to be injected into the plugin’s output, which could be executed by visitors who view affected catalog pages.
Affected Systems
WordPress sites that have the impleCode eCommerce Product Catalog plugin version 3.5.4 or older are affected. Plugins 3.5.5 and newer contain the fix. No other plugins or vendors are listed in the CNA data.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity. The EPSS score of less than 1% raises the likelihood that the flaw will be exploited in practice. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploits. The CVE states this is an unauthenticated XSS flaw, meaning the attack does not require user authentication on the site.
OpenCVE Enrichment