Junglewise Threat Intelligence

CVE-2026-15647: BeRocket Brands for WooCommerce Stored XSS in br_brand_tooltip

CVE-2026-15647 · Severity: medium · CVSS 4.4 · Published 2026-07-23

Technologies: BeRocket Brands for WooCommerce. Vendors: BeRocket.

Executive brief

The Brands for WooCommerce plugin for WordPress, which allows store owners to organize products by brand, contains a security flaw that allows certain authorized users to inject malicious scripts into the website. An attacker with Shop Manager or similar permissions could use this to run unauthorized code in the browsers of other site visitors or administrators. This could lead to unauthorized actions being performed on the site or the theft of sensitive session information.

Technical details

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'br_brand_tooltip' term meta field. This vulnerability allows authenticated attackers with high-level permissions (such as Shop Managers) to inject arbitrary web scripts. Because the payload is stored in term meta rather than standard post content, it bypasses the 'unfiltered_html' capability restrictions typically applied to these user roles. The scripts execute whenever a user accesses a page where the affected brand tooltip is displayed. The issue is present in all versions up to and including 3.8.8.

Affected products

  • BeRocket Brands for WooCommerce up to, and including, 3.8.8

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats