The Payment gateway per Product for WooCommerce plugin for WordPress is vulnerable to a type of malicious attack called Reflected Cross-Site Scripting. This type of attack can be used to inject arbitrary web scripts into pages and can be done successfully if the attacker can trick a user into clicking a link. The plugin is vulnerable to this type of attack in versions up to and including 3.2.7 due to a lack of input sanitization and output escaping.