Executive brief
VillaTheme Bopo is a WordPress plugin used by e-commerce sites to allow customers to build custom product bundles. A security flaw in this plugin allows attackers to trick a site administrator or visitor into clicking a malicious link, which then executes unauthorized code in their browser. This can lead to the theft of session cookies, unauthorized actions performed on behalf of the user, or the defacement of the website.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the VillaTheme Bopo – WooCommerce Product Bundle Builder plugin (bopo-woo-product-bundle-builder) for WordPress. The flaw stems from the improper neutralization of input during web page generation, allowing an unauthenticated attacker to inject malicious scripts into a victim's browser. Exploitation requires a user to interact with a specially crafted link or form. Successful exploitation can result in the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or administrative account takeover. The issue is fixed in version 1.2.1.
Affected products
- VillaTheme Bopo – WooCommerce Product Bundle Builder <= 1.2.0
Timeline
- 2026-06-03: disclosed: Reported by dutafi to Patchstack
- 2026-07-08: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record
- 2026-07-08: patched: Version 1.2.1 released to address the vulnerability