Impact
Improper neutralization of user input in the Flintop Free Gifts for WooCommerce plugin leads to stored cross‑site scripting. A malicious payload entered into any data field that the plugin stores can subsequently be executed on pages viewed by site visitors. This flaw is a classic input validation weakness identified as CWE‑79.
Affected Systems
WordPress sites that have the Flintop Free Gifts for WooCommerce plugin installed, version 13.1.0 or older.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity, however the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA's KEV catalog. Based on the description, attackers could inject malicious script code into any stored data field handled by the plugin; once the data is rendered, the script executes in the browsers of visitors.
OpenCVE Enrichment