Executive brief
The GTM4WP plugin for WordPress, which integrates Google Tag Manager with website data, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the site. By placing a guest order through WooCommerce and entering a script into a billing field (like a first name), an attacker can cause that script to run in the browser of any user or administrator who views the order details. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the GTM4WP plugin for WordPress due to improper sanitization and escaping of WooCommerce billing fields. The vulnerability is exploitable by unauthenticated attackers who place a guest checkout order containing a JavaScript payload in fields such as the billing first name. For an exploit to be successful, the 'GTM4WP_OPTION_INTEGRATE_WCORDERDATA' (WooCommerce order data integration) option must be enabled. When an administrator or user views the affected order data, the injected script executes within their browser context. This issue is fixed in version 1.22.4.
Affected products
- duracelltomi GTM4WP – A Google Tag Manager (GTM) plugin for WordPress <= 1.22.3
Timeline
- 2026-07-29: advisory: NVD publication date
- 2026-07-29: disclosed: Wordfence vulnerability report published
References
- https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php
- https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php
- https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/integration/woocommerce.php
- https://plugins.trac.wordpress.org/browser/duracelltomi-google-tag-manager/tags/1.22.3/public/frontend.php
- https://plugins.trac.wordpress.org/changeset/3618063/duracelltomi-google-tag-manager/trunk/public/frontend.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fduracelltomi-google-tag-manager/tags/1.22.3&new_path=%2Fduracelltomi-google-tag-manager/tags/1.22.4
- https://www.wordfence.com/threat-intel/vulnerabilities/id/03542812-b6e5-421d-9ba6-43f1c779940f?source=cve