Executive brief
The Brands for WooCommerce plugin for WordPress, which helps store owners manage and display product brands, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'width' attribute within its shortcode functionality. The flaw is located in the Divi builder addon component. Authenticated attackers with contributor-level permissions or higher can exploit this by embedding malicious scripts into a post or page via the shortcode. Because the input is not properly neutralized before being stored and subsequently rendered, the script executes in the context of any user's browser who views the page. The vulnerability affects all versions up to and including 3.8.8.
Affected products
- BeRocket Brands for WooCommerce up to, and including, 3.8.8
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php
- https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/addons/divi_shortcode/divi-builder.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerce
- https://www.wordfence.com/threat-intel/vulnerabilities/id/3efb5f5c-64d2-4819-82bf-45574df94209?source=cve