Executive brief
A vulnerability exists in a popular WooCommerce extension used for calculating product costs and profits. An attacker with basic contributor-level access to the website can inject malicious scripts into pages. These scripts will automatically run when other users, including site administrators, visit the affected pages, potentially leading to unauthorized actions or data theft.
Technical details
The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes. This vulnerability allows authenticated attackers with contributor-level permissions or higher to inject arbitrary web scripts into pages. These scripts are stored on the server and execute in the context of any user's browser who views the compromised page. The issue affects all versions up to and including 4.1.0. A patch has been released in subsequent updates.
Affected products
- Algoritmika Cost of Goods: Product Cost & Profit Calculator for WooCommerce Up to and including 4.1.0
Timeline
- 2026-05-13: disclosed: Initial disclosure date
- 2026-05-13: advisory: NVD and Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/cost-of-goods-for-woocommerce/tags/4.1.0/includes/class-alg-wc-cog-products.php
- https://plugins.trac.wordpress.org/browser/cost-of-goods-for-woocommerce/tags/4.1.0/includes/class-alg-wc-cog-products.php
- https://plugins.trac.wordpress.org/browser/cost-of-goods-for-woocommerce/tags/4.1.0/includes/class-alg-wc-cog-products.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3524832%40cost-of-goods-for-woocommerce&new=3524832%40cost-of-goods-for-woocommerce&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/aedde7a7-018d-45f9-8f67-f4ea01be894e?source=cve