Executive brief
Swatchly is a WordPress plugin that enables product variation swatches for WooCommerce stores. An unauthenticated cross-site scripting (XSS) vulnerability in versions up to 1.4.13 allows attackers to inject malicious scripts into affected websites. This can lead to theft of visitor data, account hijacking, or malware distribution without requiring the attacker to have login credentials or direct administrative access.
Technical details
The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in Swatchly – WooCommerce Variation Swatches for Products plugin versions 1.4.13 and earlier. The XSS is exploitable by unauthenticated users, though successful exploitation may require user interaction (such as visiting a malicious link or crafted page). Attackers can inject arbitrary JavaScript into the site, enabling session hijacking, credential theft, or malware delivery to site visitors. The vulnerability has been patched in version 1.4.14 and later. A mitigation rule is available through Patchstack to block attacks until patching is completed.
Affected products
- Swatchly WooCommerce Variation Swatches for Products <=1.4.13
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Fix released in version 1.4.14