Junglewise Threat Intelligence

CVE-2026-7436: WPClever WPC Badge Management for WooCommerce Stored XSS in Shortcode

CVE-2026-7436 · Severity: medium · CVSS 6.4 · Published 2026-07-29

Executive brief

WPC Badge Management for WooCommerce is a WordPress plugin used to display promotional badges (like 'Sale' or 'Best Seller') on online stores. A security flaw allows users with contributor-level access or higher to inject malicious scripts into these badges. When other users or customers view the affected store pages, the script executes, potentially leading to unauthorized actions or data theft.

Technical details

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 3.1.6. The vulnerability exists within the 'text' attribute of the `wpcbm_best_seller` shortcode due to insufficient input sanitization and output escaping. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into a page. These scripts will execute in the browser of any user who visits the compromised page. The issue was addressed in version 3.1.7.

Affected products

  • WPClever WPC Badge Management for WooCommerce 0 - 3.1.6

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched: Fixed in version 3.1.7

References

Related threats