Impact
The WCFM Marketplace plugin contains a contributor‑level Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into pages viewed by other users. This weakness, categorized as CWE‑79, can lead to compromised user sessions, defacement, or theft of sensitive information without requiring elevated privileges.
Affected Systems
The vulnerability affects the WordPress WCFM Marketplace plugin from the vendor WC Lovers, specifically all releases up to and including version 3.8.2. Users running these or earlier versions are exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable from a web interface that accepts contributor input; therefore, any active contributor with access to the plugin’s input fields can trigger the XSS attack.
OpenCVE Enrichment