What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XLPlugins User Email Verification for WooCommerce plugin <= 3.5.0 versions.
Explanation of Vulnerability in Simple Terms
The User Email Verification for WooCommerce plugin through version 3.5.0 contains a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in users' browsers when they interact with affected pages. The vulnerability requires user interaction and can affect multiple users across the site. Update to a version newer than 3.5.0 to resolve this issue.
What an attacker can do
Inject malicious scripts that run in users' browsers and steal data or perform actions on their behalf.
Potential impact on your site
Customer accounts and data at risk; attackers can steal login credentials, payment info, or perform unauthorized actions.
Conditions required to exploit
No authentication required. Victim must visit a page containing the attacker's malicious input.
Key dates
External resources
Related vulnerabilities