Junglewise Threat Intelligence

CVE-2026-15794: BeRocket Grid/List View for WooCommerce Stored XSS in Shortcode

CVE-2026-15794 · Severity: medium · CVSS 6.4 · Published 2026-07-23

Vendors: BeRocket.

Executive brief

The Grid/List View for WooCommerce plugin for WordPress, which helps online stores display products in different layouts, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will run automatically when other users visit the affected pages, potentially leading to unauthorized actions or data theft.

Technical details

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'position' attribute of its shortcode. Authenticated attackers with contributor-level permissions or higher can exploit this to inject arbitrary JavaScript. By utilizing the 'all_page="1"' attribute, attackers can force the malicious payload to render across any page on the site, rather than just shop or category pages. This vulnerability is present in all versions up to and including 3.0.9. A patch appears to be available in subsequent updates (changeset 3611837).

Affected products

  • BeRocket Grid/List View for WooCommerce up to, and including, 3.0.9

Timeline

  • 2026-07-23: advisory: NVD publication date
  • 2026-07-23: disclosed: Wordfence disclosure date

References