Junglewise Threat Intelligence

CVE-2025-14767: WPClever WPC Badge Management for WooCommerce Stored XSS in Shortcode

CVE-2025-14767 · Severity: medium · CVSS 5.5 · Published 2026-05-13

Executive brief

WPC Badge Management for WooCommerce is a WordPress plugin used to display promotional badges (like 'Best Seller' or 'On Sale') on e-commerce sites. A security flaw allows users with Shop Manager-level access to embed malicious scripts into these badges. If exploited, these scripts will run in the browsers of any visitor or administrator who views the affected store pages, potentially leading to unauthorized actions or data theft.

Technical details

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'text' attribute of the 'wpcbm_best_seller' shortcode. Authenticated attackers with high-level permissions (Shop Manager and above) can inject arbitrary web scripts into the shortcode configuration. These scripts are stored on the server and execute in the context of a user's browser whenever they visit a page where the malicious badge is rendered. The vulnerability is fixed in version 3.1.7.

Affected products

  • WPClever WPC Badge Management for WooCommerce up to, and including, 3.1.6

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2025-02-15: patched: Based on changelog version 3.1.7 release date proximity

References

Related threats