Impact
The Bopo – WooCommerce Product Bundle Builder plugin processes user‑supplied data when generating product bundle pages. Because it does not properly neutralize input in the URL or form parameters, an attacker can inject arbitrary JavaScript that is reflected back into the browser. This is a classic reflected XSS flaw, classified as CWE‑79, and it enables the execution of malicious scripts, potentially leading to cookie theft, session hijacking, phishing, or defacement.
Affected Systems
Every WordPress site that has installed VillaTheme's Bopo – WooCommerce Product Bundle Builder plugin with a version number of 1.2.0 or earlier is vulnerable. The issue applies from the earliest available release up to and including 1.2.0, affecting all sites that have not upgraded beyond this version threshold.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but still present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through unauthenticated users who submit crafted URLs or form data containing malicious code; once a visitor loads the affected page, the script executes in the victim’s browser. No privileged access is required for exploitation.
OpenCVE Enrichment