Impact
The vulnerability is unauthenticated reflected cross‑site scripting in the MultiParcels Shipping For WooCommerce plugin, allowing an attacker to inject malicious HTML or JavaScript that is reflected back to the browser when a crafted request is made. Such payloads can steal session cookies, deface the site, or redirect users to phishing sites, compromising confidentiality, integrity, and potentially availability if the attacker subverts user trust.
Affected Systems
Vulnerable versions of the WordPress MultiParcels Shipping For WooCommerce plugin up to and including 1.30.36. The plugin is distributed by the vendor multiparcels and is used by WooCommerce‑based e‑commerce sites.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity of this reflected XSS flaw. No EPSS score is published, and the vulnerability is not in the CISA KEV catalog. The flaw can be exploited by sending a crafted URL to any user, without authentication or special permissions, and is typically straightforward for automated tools to leverage. Attackers gain ability to inject scripts that run in victims’ browsers, potentially leading to credential theft or sabotage.
OpenCVE Enrichment