Executive brief
A vulnerability exists in the Customize My Account for WooCommerce plugin, which is used to modify the customer dashboard on WordPress e-commerce sites. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to unauthorized actions being performed on behalf of the user, such as redirecting them to malicious websites or stealing session information.
Technical details
The Customize My Account for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input in versions up to and including 4.3.9. An unauthenticated attacker can exploit this by sending a specially crafted link to a user; if the user clicks the link, the malicious script is executed within the context of their browser session. This is classified as CWE-79 and carries a CVSS 3.1 score of 7.1. The issue was addressed in version 4.3.10.
Affected products
- SysBasics Customize My Account for WooCommerce <= 4.3.9
Timeline
- 2026-05-14: disclosed: Reported by dutafi
- 2026-07-01: advisory: Patchstack advisory published
- 2026-07-02: patched: Version 4.3.10 released to address the vulnerability