Junglewise Threat Intelligence

CVE-2026-57758: BeRocket Permalink Manager for WooCommerce CSRF to Stored XSS

CVE-2026-57758 · Severity: high · CVSS 7.1 · Published 2026-07-02

Vendors: BeRocket.

Executive brief

A vulnerability exists in the Permalink Manager for WooCommerce plugin, which is used to customize website link structures for online stores. An attacker could trick a site administrator into performing unintended actions, such as changing site settings or injecting malicious scripts, by getting them to click a specially crafted link. This could lead to unauthorized changes to the store's configuration or the compromise of administrative accounts.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the BeRocket Permalink Manager for WooCommerce plugin through version 1.0.8.2. The issue stems from a lack of proper nonce validation on sensitive administrative functions, allowing an unauthenticated attacker to craft a malicious request. If a logged-in administrator interacts with a malicious link or page, the attacker can trigger actions on their behalf, potentially leading to Stored Cross-Site Scripting (XSS). As of the advisory date, no official patch has been released, and users are advised to exercise caution with administrative sessions.

Affected products

  • BeRocket Permalink Manager for WooCommerce <= 1.0.8.2

Timeline

  • 2026-05-10: disclosed: Reported by dodoh4t
  • 2026-07-02: advisory: Published by Patchstack and NVD

References