Impact
The vulnerability allows malicious script injection into WordPress checkout pages through the Checkout Field Editor for WooCommerce – Checkout Manager plugin, creating a classic cross‑site scripting condition. When exploited, an attacker could execute code in the context of visitors browsing the shop, potentially exposing session cookies, defacing pages, or redirecting users to malicious sites.
Affected Systems
The flaw exists in all installations of the acowebs Checkout Field Editor for WooCommerce – Checkout Manager plugin through version 3.0.5. The plugin is commonly used within WordPress sites running the WooCommerce e‑commerce platform.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity vulnerability. The EPSS score is 0.0014, indicating a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s admin interface, where an attacker with authorized access can insert malicious code into custom checkout fields that are later rendered on the public checkout page.
OpenCVE Enrichment