Impact
The flaw is an improper neutralization of input during web page generation that allows reflected cross‑site scripting. An attacker can supply specially crafted data that is echoed back into the page, enabling the execution of arbitrary JavaScript in the victim’s browser. This can lead to session hijacking, credential theft, or other attacks performed in the context of the authenticated user. The weakness is a classic unsanitized input error, listed as CWE‑79.
Affected Systems
The vulnerability exists in Mamunur Rashid’s WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin, versions up through 3.4.1. Users running any of these versions are potentially exposed.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.1, indicating a moderate‑to‑high severity. No EPSS score is available, and it is not yet listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not been observed. The likely attack vector is via reflected input in plugin interfaces, requiring the attacker to trick a user into visiting a crafted URL or submitting a form containing malicious payloads.
OpenCVE Enrichment