Executive brief
The Cost of Goods by PixelYourSite plugin for WordPress, which helps e-commerce sites track product costs and profit margins, contains a security flaw that allows attackers to inject malicious scripts into the website. Because this vulnerability can be exploited by unauthenticated users, an attacker could potentially hijack administrator sessions, redirect customers to fraudulent websites, or deface the store. This poses a significant risk to the integrity of the website and the security of customer data.
Technical details
The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'csvdata[0][cost_of_goods_value]' parameter. This vulnerability allows unauthenticated remote attackers to submit malicious JavaScript payloads that are stored on the server. When a site administrator or visitor views the affected page, the script executes within the context of their browser session. This can lead to session hijacking, unauthorized administrative actions, or site defacement. The issue affects all versions up to and including 1.2.12.
Affected products
- PixelYourSite Cost of Goods by PixelYourSite Up to, and including, 1.2.12
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory