Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw that allows malicious scripts to be injected when visitors interact with the Music Player for WooCommerce plugin. This flaw can lead to the execution of arbitrary JavaScript on a user’s browser, potentially enabling attackers to hijack sessions, steal credentials, deface the site, or serve phishing content. The weakness is classified as CWE‑79, reflecting a failure to properly escape or validate user input before rendering it as part of the page.
Affected Systems
The affected product is codepeople’s Music Player for WooCommerce plugin for WordPress, versions up to and including 1.8.9. Users running any of these releases are vulnerable. No other products or versions are documented as affected.
Risk and Exploitability
The plugin’s XSS flaw is rated with a CVSS score of 7.1, indicating high severity, while EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Exploitation is straightforward: an attacker can embed malicious script in plugin data accessible to any visitor, without requiring authentication. Since any user can trigger the flaw, the risk of widespread impact is significant, especially on sites with high traffic or sensitive user interactions.
OpenCVE Enrichment