Impact
An unauthenticated Cross‑Site Scripting (XSS) flaw exists in the WordPress plugin Local Delivery Drivers for WooCommerce up to version 3.0.0. The vulnerability allows an attacker to inject arbitrary scripts that execute in the victim’s browser while interacting with the plugin’s interface. Such scripts can steal session cookies, deface the site, or redirect users to malicious content, thereby jeopardizing confidentiality and integrity of the site’s data.
Affected Systems
The flaw affects the WordPress plugin Local Delivery Drivers for WooCommerce (developed by PowerfulWP) where the version is 3.0.0 or earlier. No further sub‑versions are listed, so any installation of the plugin not updated beyond 3.0.0 is affected.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity, and the eth30^S score is not available, indicating no current exploitation data. The vulnerability is listed as not part of the CISA KEV catalog. Because it is unauthenticated, a remote attacker can trigger it from any web browser by requesting a crafted URL or entering malicious data into an exposed field, making it potentially exploitable by a wide user base with no special permissions.
OpenCVE Enrichment