Description
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross‑Site Scripting (XSS) flaw exists in the WordPress plugin Local Delivery Drivers for WooCommerce up to version 3.0.0. The vulnerability allows an attacker to inject arbitrary scripts that execute in the victim’s browser while interacting with the plugin’s interface. Such scripts can steal session cookies, deface the site, or redirect users to malicious content, thereby jeopardizing confidentiality and integrity of the site’s data.

Affected Systems

The flaw affects the WordPress plugin Local Delivery Drivers for WooCommerce (developed by PowerfulWP) where the version is 3.0.0 or earlier. No further sub‑versions are listed, so any installation of the plugin not updated beyond 3.0.0 is affected.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity, and the eth30^S score is not available, indicating no current exploitation data. The vulnerability is listed as not part of the CISA KEV catalog. Because it is unauthenticated, a remote attacker can trigger it from any web browser by requesting a crafted URL or entering malicious data into an exposed field, making it potentially exploitable by a wide user base with no special permissions.

Generated by OpenCVE AI on August 13, 2026 at 16:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Local Delivery Drivers for WooCommerce plugin to the latest version that removes the XSS flaw.
  • If the plugin is not required, completely uninstall or disable it to eliminate the attack surface.
  • Place the site in maintenance mode or restrict access to the admin area until the plugin is updated to mitigate immediate risk.

Generated by OpenCVE AI on August 13, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
Title WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:47:34.247Z

Reserved: 2026-07-27T09:00:40.310Z

Link: CVE-2026-66468

cve-icon Vulnrichment

Updated: 2026-08-13T14:24:51.726Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:08.237

Modified: 2026-08-13T16:18:45.293

Link: CVE-2026-66468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')