Impact
Unauthenticated cross‑site scripting has been discovered in the WordPress Product Feed Manager plugin for versions up to 7.6.1. This weakness allows an attacker to inject arbitrary script code that will be executed in the browsers of visitors who view pages that contain the plugin’s output. Based on the nature of XSS, the attacker could inject and execute arbitrary JavaScript in visitors’ browsers, potentially allowing theft of session cookies or site defacement; these consequences are inferred annotations rather than direct statements from the CVE text.
Affected Systems
RexTheme’s Product Feed Manager plugin is affected for all releases up to and including version 7.6.1. Any WordPress site that uses that plugin should upgrade to version 7.6.2 or later to eliminate the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity, while the EPSS score is <1%, showing a very low exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector, inferred from typical cross‑site scripting flows, involves unauthenticated submission of malicious input via plugin-controlled fields or crafted URLs, which the plugin then renders without proper sanitization. If the plugin is active and the site is publicly accessible, this vulnerability is relatively easy to exploit for any attacker with the ability to drive traffic to the affected pages.
OpenCVE Enrichment