Impact
The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable because the csvdata[0][cost_of_goods_value] parameter is accepted without adequate sanitization or escaping. A malicious user can store arbitrary JavaScript code in the plugin’s data import, causing the code to run when any site visitor views a page that pulls the injected data. This stored XSS flaw could be used to hijack user sessions, deface content, redirect victims, or otherwise compromise the security of the site, as identified by CWE‑79.
Affected Systems
The vulnerability affects the PixelYourSite "Cost of Goods by PixelYourSite" plugin for WordPress versions 1.2.12 and earlier. No other vendor or product versions are listed as affected.
Risk and Exploitability
With a CVSS score of 7.2 the flaw carries a medium‑high severity rating. The EPSS score is unavailable and the issue is not listed in CISA’s KEV catalog. Because the attack vector is unauthenticated and can be exercised via the public CSV import interface, the likelihood of exploitation is significant for any active site using the affected plugin version.
OpenCVE Enrichment