Impact
The vulnerability is a stored cross‑site scripting flaw arising when user‑supplied attributes of the "avalon23_qr" shortcode are inserted directly into single‑quoted HTML attributes without proper sanitization or escaping. An attacker with Contributor-level access can inject arbitrary JavaScript that is stored in the content and executed in the browsers of any visitor who views a page containing the shortcode, enabling session hijacking, defacement, or phishing.
Affected Systems
WordPress sites that have installed the Avalon23 Products Filter for WooCommerce plugin by ParadigmTools are affected. All releases up through version 1.1.6 are vulnerable; newer versions are not confirmed to contain the flaw.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity. It is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the Contributor level or higher and involves modifying the shortcode attributes. Once injected, the malicious payload remains stored until the plugin is upgraded or the shortcode content is removed, presenting a persistent threat to all site visitors.
OpenCVE Enrichment