Executive brief
StoreGrowth is a WordPress plugin used by e-commerce sites to boost sales through features like popups and special offers. A security flaw allows unauthorized individuals to modify the plugin's settings, specifically the products displayed in sales popups. This could be used by attackers to manipulate store promotions or display unauthorized product information to customers.
Technical details
The StoreGrowth plugin for WordPress (versions up to 2.1.0) fails to implement proper authorization checks on its AJAX actions. While the plugin uses an 'ajd_protected' nonce for security, this nonce is leaked to unauthenticated visitors on every frontend page via the BoGo module's wp_localize_script call. Consequently, an unauthenticated attacker can use this leaked nonce to bypass the intended security gate and overwrite the 'spsg_popup_products' database option with arbitrary data. This is classified as a Missing Authorization (CWE-862) vulnerability.
Affected products
- weDevs StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce <= 2.1.0
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
References
- https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/bogo/includes/EnqueueScript.php
- https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php
- https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php
- https://plugins.trac.wordpress.org/browser/storegrowth-sales-booster/tags/2.1.0/modules/sales-pop/includes/Ajax.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3619581%40storegrowth-sales-booster&new=3619581%40storegrowth-sales-booster
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a1e07c9c-7d35-41b4-aaa1-f37c4f10f7ac?source=cve