Impact
The Custom Payment Gateways for WooCommerce plugin is vulnerable to stored cross‑site scripting through the 'alg_wc_cpg_input_fields' parameter because input sanitization is insufficient, allowing an unauthenticated attacker to embed malicious scripts that are stored and executed whenever a checkout page is accessed. This flaw can be triggered by a crafted checkout POST request without requiring any custom input fields to be configured.
Affected Systems
WordPress installations that have the Custom Payment Gateways for WooCommerce plugin from dhruvin and are running any version up to and including 2.1.0 are affected. Versions beyond 2.1.0 are not vulnerable, but the plugin should be up‑to‑date to avoid this issue.
Risk and Exploitability
The flaw has a CVSS score of 7.2, classifying it as high severity. EPSS data is not available, so the exact likelihood of exploitation is unknown, though the vulnerability is publicly documented and can be abused by unauthenticated guests via checkout POST requests; it is not listed in the CISA KEV catalog.
OpenCVE Enrichment