Impact
QuantumCloud ChatBot for eCommerce – WoowBot plugin contains a Stored XSS flaw that allows an attacker to inject malicious script into a web page viewed by users. The vulnerability results from improper neutralization of input during page generation, enabling attackers to execute arbitrary JavaScript when the affected content is rendered.
Affected Systems
QuantumCloud’s ChatBot for eCommerce – WoowBot plugin is affected in all releases up to and including version 4.6.1. The plugin is a WordPress extension used on eCommerce sites for chat functionality, and any WordPress installation that has this plugin version deployed is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑severity risk, and the EPSS score of less than 1 % suggests this vulnerability is unlikely to be found in the wild. The vulnerability is not listed in the CISA KEV catalog. Because it is stored XSS, the likely attack vector involves an attacker supplying malicious content through the chat plugin, which is later stored and rendered. No prerequisite conditions are specified, meaning that an attacker only needs to supply malicious content that will be stored and later displayed.
OpenCVE Enrichment