Executive brief
The Advanced Woo Labels plugin for WordPress, which is used to create custom product badges for e-commerce sites, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into the website. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Advanced Woo Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'bg_color' parameter. This vulnerability exists in all versions up to and including 2.48. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser session whenever they visit the page where the malicious label is displayed. The vulnerability is tracked as CWE-79 and has a CVSS score of 6.4.
Affected products
- mihail-barinov Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.48
Timeline
- 2026-08-01: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/advanced-woo-labels.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/admin/class-awl-admin.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/awl-functions.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php
- https://plugins.trac.wordpress.org/browser/advanced-woo-labels/tags/2.48/includes/class-awl-label-view.php