Executive brief
The Brands for WooCommerce plugin for WordPress, which helps store owners organize and display product brands, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically whenever a visitor or administrator views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'style' attribute within its shortcode implementation. Authenticated attackers with contributor-level permissions or higher can exploit this by embedding malicious scripts into a post or page using the shortcode. When other users, including administrators, view the affected content, the script executes in their browser session. This vulnerability is present in all versions up to and including 3.8.8. A patch has been identified in recent changesets to address the improper neutralization of input.
Affected products
- BeRocket Brands for WooCommerce up to, and including, 3.8.8
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory
References
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/berocket/includes/functions.php
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/includes/shortcodes.php
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/trunk/templates/catalog.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerce
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8fa3bcb9-df3e-4042-a28b-3d09bfebeebc?source=cve