Impact
Subscriber Cross Site Scripting (XSS) exists in the AfterShip Tracking plugin through version 1.18.1, allowing untrusted input to be rendered as arbitrary HTML or JavaScript. The flaw is a classic CWE‑79 vulnerability that can enable an attacker to inject malicious scripts when a subscriber interacts with the plugin’s interface, potentially leading to credential theft, session hijacking, or defacement.
Affected Systems
WordPress sites that use the AfterShip Tracking plugin from AfterShip & Automizely, specifically versions up to and including 1.18.1. The vulnerability affects any instance where subscriber data is displayed without proper sanitization.
Risk and Exploitability
The vulnerability is scored a moderate CVSS 6.5, indicating a notable impact on confidentiality, integrity, and availability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through malicious subscriber input that the plugin renders unsanitized, suggesting that any attacker who can submit such input or already has access to the subscriber interface could exploit the flaw.
OpenCVE Enrichment