Impact
Improper neutralization of input during web page generation creates a DOM‑based cross‑site scripting flaw that lets an attacker inject arbitrary JavaScript into pages served by the Active Products Tables for WooCommerce plugin. This can enable session hijacking, defacement, or the execution of malicious payloads in the context of the affected site. Based on the description, it is inferred that an attacker would need to submit crafted data to the plugin’s product table fields or to URLs used by the plugin, triggering the XSS in the user’s browser.
Affected Systems
The vulnerability affects the RealMag777 Active Products Tables for WooCommerce plugin, impacting all releases from the initial version through version 1.1.0. Users running any of these versions are exposed if they permit untrusted inputs to be processed by the plugin.
Risk and Exploitability
The CVSS score of 7.1 signals a high level of impact less than 1 % indicates that exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. Attackers could potentially trigger the XSS by submitting malicious content to product table fields or by leading to the execution of arbitrary code in the victim’s browser.
OpenCVE Enrichment