Executive brief
A vulnerability exists in a popular WordPress plugin used to customize WooCommerce customer account pages. An attacker could trick a store administrator or shop manager into clicking a malicious link, allowing the attacker to execute unauthorized scripts within the victim's browser session. This could lead to unauthorized actions being performed on the site or the theft of sensitive session information.
Technical details
The SysBasics Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'tab' parameter within the plugin_options_page() function. An unauthenticated attacker can exploit this by crafting a malicious URL and tricking a logged-in user with Shop Manager-level access or higher into clicking it. Because the vulnerable code is rendered within the WordPress admin dashboard, the attack requires user interaction from a privileged user. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser. A patch appears to be available in versions following 4.3.6.
Affected products
- SysBasics (phppoet) Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager up to, and including, 4.3.6
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory
References
- https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/tags/4.3.6/include/admin/admin_settings.php
- https://plugins.trac.wordpress.org/browser/customize-my-account-for-woocommerce/tags/4.3.6/include/admin/admin_settings.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3571110%40customize-my-account-for-woocommerce&new=3571110%40customize-my-account-for-woocommerce&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/74c1bc1d-27f1-4953-8ebd-9396fce0f834?source=cve