Impact
The Cart Lift plugin contains a Stored XSS flaw due to failure to escape user‑supplied input in generated web pages; attackers can inject malicious scripts that execute in visitors’ browsers.
Affected Systems
The vulnerability impacts RexTheme Cart Lift installations for WordPress up to version 3.1.57; any site running this or earlier releases is exposed.
Risk and Exploitability
The CVSS score of 7.1 signals high severity, while an EPSS score of less than 1% indicates a low probability of exploitation, and the flaw is not listed in CISA KEV. Nonetheless, the stored nature of the XSS means that an attacker who can add or modify content via the plugin can execute arbitrary scripts in users’ browsers; the attack vector is inferred to be through the plugin’s input handling.
OpenCVE Enrichment