Impact
The vulnerability is an unauthenticated Cross Site Scripting (XSS) flaw in the Paymob for WooCommerce WordPress plugin versions up to and including 4.1.10. An attacker can inject arbitrary JavaScript into a page viewed by site visitors, potentially leading to credential theft, defacement, or execution of malicious actions in the context of the site. The flaw arises from insufficient sanitization of user‑controlled input, classified as CWE-79.
Affected Systems
WordPress Paymob for WooCommerce plugin made by Paymob, affecting all installations using version 4.1.10 or earlier.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated; an attacker can exploit the flaw by sending a crafted request to the vulnerable plugin’s interface from any network location, without the need for privileged access.
OpenCVE Enrichment