Impact
A Cross‑Site Scripting (XSS) flaw exists in the WooCommerce Multilingual & Multicurrency plugin that allows malicious code to be injected through subscriber data fields. The flaw, identified as CWE‑79, can lead to the execution of arbitrary scripts in the victim’s browser, potentially enabling session hijacking, credential theft, or defacement of the site.
Affected Systems
The vulnerability affects the WooCommerce Multilingual & Multicurrency plugin developed by Amir Helzer, with versions 5.5.6 and earlier. No additional product or vendor versions were listed in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available, so current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the plugin’s web interface that accepts user‑supplied subscriber data; however, this inference is made based on typical XSS scenarios, as the description does not specify the exact entry point.
OpenCVE Enrichment