Executive brief
A vulnerability exists in the Permalink Manager for WooCommerce plugin, which is used to customize website link structures for online stores. An attacker could trick a site administrator into performing unintended actions, such as changing site settings or injecting malicious scripts, by getting them to click a specially crafted link. This could lead to unauthorized changes to the store's configuration or the compromise of administrative accounts.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the BeRocket Permalink Manager for WooCommerce plugin through version 1.0.8.2. The issue stems from a lack of proper nonce validation on sensitive administrative functions, allowing an unauthenticated attacker to craft a malicious request. If a logged-in administrator interacts with a malicious link or page, the attacker can trigger actions on their behalf, potentially leading to Stored Cross-Site Scripting (XSS). As of the advisory date, no official patch has been released, and users are advised to exercise caution with administrative sessions.
Affected products
- BeRocket Permalink Manager for WooCommerce <= 1.0.8.2
Timeline
- 2026-05-10: disclosed: Reported by dodoh4t
- 2026-07-02: advisory: Published by Patchstack and NVD