Impact
An unauthenticated Cross Site Scripting vulnerability in the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin for WordPress allows attackers to inject arbitrary scripts into the web page. The flaw is present in all releases up to and including version 2.10.0. By executing malicious code in the victim's browser, an attacker could potentially hijack sessions, deface content, or perform other browser‑based attacks.
Affected Systems
Affected systems are WordPress sites that have installed the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin version 2.10.0 or earlier; the issue is tied to the plugin's handling of shipping method data and is specific to the WooCommerce integration.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may be limited or not yet observed. Because authentication is not required, any visitor to a site using the affected plugin can trigger the XSS, which increases the attack surface and potential impact.
OpenCVE Enrichment