Impact
Unauthenticated cross-site scripting exists in the Premmerce Permalink Manager for WooCommerce plugin through version 2.3.13, allowing attackers to inject arbitrary script into the web page. The injected code can be used to hijack user sessions, steal credentials, or manipulate the site content. This weakness aligns with CWE-79 and can directly compromise the confidentiality and integrity of user data.
Affected Systems
The vulnerability affects WordPress sites that use the Premmerce Permalink Manager for WooCommerce plugin versions up to and including 2.3.13. Sites employing the plugin during that version range are susceptible to exploitation until the plugin is upgraded.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, although the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is unauthenticated and likely involves manipulating URL parameters or custom permalink inputs that are rendered unescaped. Successful exploitation would allow an attacker to inject scripts that run in the victim’s browser context.
OpenCVE Enrichment