Impact
The Bopo – WooCommerce Product Bundle Builder plugin contains an Improper Neutralization of Input During Web Page Generation vulnerability that permits reflected cross‑site scripting. User supplied data that is incorporated into URLs or form parameters is not correctly sanitized, leading to arbitrary code being reflected back to the client and executed in the victim’s browser.
Affected Systems
Any WordPress site that has installed VillaTheme’s Bopo – WooCommerce Product Bundle Builder plugin with a version number of 1.2.0 or earlier is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while an EPSS score of less than 1 % suggests that exploitation is currently unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through unauthenticated users who send crafted URLs or form data to the site; the reflected input is executed without additional privileges.
OpenCVE Enrichment