Impact
The vulnerability is an XSS flaw that allows an attacker to inject executable script into content rendered by the YITH WooCommerce Tab Manager plugin. If an attacker can influence the text of a custom tab, that content may be executed in the browsers of site visitors, potentially exposing session data and other sensitive information to the attacker.
Affected Systems
This issue affects installations of the YITHEMES YITH WooCommerce Tab Manager plugin at version 2.15.0 or earlier, regardless of the underlying WordPress version, because the flaw resides entirely in the plugin code.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity, while the EPSS score is not available, so exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly documented, but the plugin’s interface for creating or editing custom tabs is likely the entry point that could be abused. No known public exploits have been reported, so the threat remains theoretical at this time.
OpenCVE Enrichment