Executive brief
The GLS Shipping for WooCommerce plugin for WordPress, which integrates GLS shipping services into online stores, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a store administrator or customer into clicking a specifically crafted link, an attacker could potentially steal session information or perform unauthorized actions on their behalf. This issue affects all versions of the plugin up to and including 1.4.0.
Technical details
The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'failed_orders' parameter. This vulnerability exists in all versions up to and including 1.4.0. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing executable JavaScript and tricking a user into interacting with it. If successful, the script executes within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. A patch appears to be available in the plugin's changeset 3459927.
Affected products
- GLS GLS Shipping for WooCommerce Up to, and including, 1.4.0
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory