Description
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Scripting vulnerability in the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin for WordPress allows attackers to inject arbitrary scripts into the web page. The flaw is present in all releases up to and including version 2.10.0. By executing malicious code in the victim's browser, an attacker could potentially hijack sessions, deface content, or perform other browser‑based attacks.

Affected Systems

Affected systems are WordPress sites that have installed the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin version 2.10.0 or earlier; the issue is tied to the plugin's handling of shipping method data and is specific to the WooCommerce integration.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate‑to‑high severity level. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may be limited or not yet observed. Because authentication is not required, any visitor to a site using the affected plugin can trigger the XSS, which increases the attack surface and potential impact.

Generated by OpenCVE AI on August 13, 2026 at 16:09 UTC.

Remediation

Vendor Solution

Update the WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin to the latest available version (at least 3.0.0).


OpenCVE Recommended Actions

  • Update the Colissimo Officiel: Méthodes de livraison pour WooCommerce plugin to version 3.0.0 or newer, which eliminates the XSS flaw.
  • Verify that all user‑generated content provided to the plugin, such as shipping method names or descriptions, is properly escaped or sanitized before rendering.
  • If the shipping method plugin is not essential to your WooCommerce store, remove or disable it to eliminate the vulnerability surface.

Generated by OpenCVE AI on August 13, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
Title WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:21:39.897Z

Reserved: 2026-07-27T14:01:09.905Z

Link: CVE-2026-66697

cve-icon Vulnrichment

Updated: 2026-08-13T15:21:35.447Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:10.647

Modified: 2026-08-13T16:18:47.083

Link: CVE-2026-66697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')