Executive brief
The NS Product icon badge plugin for WordPress, which allows site owners to add visual badges to product images, is vulnerable to a security flaw. An attacker can trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to the improper use of the PHP_SELF variable within the ns_addNewOptionsPage.php file. The vulnerability exists in all versions up to and including 1.2.4 because the plugin fails to sufficiently sanitize input and escape output. An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a user (such as an administrator) into clicking it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions.
Affected products
- NS Product icon badge plugin for WordPress NS Product icon badge Up to and including 1.2.4
Timeline
- 2026-05-27: advisory: Advisory published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/product-icon-badge/tags/1.2.4/ns_IBA_mainOptions/ns_addNewOptionsPage.php
- https://plugins.trac.wordpress.org/browser/product-icon-badge/tags/1.2.4/ns_IBA_mainOptions/ns_addNewOptionsPage.php
- https://plugins.trac.wordpress.org/browser/product-icon-badge/tags/1.2.4/ns_IBA_mainOptions/ns_addNewOptionsPage.php
- https://plugins.trac.wordpress.org/browser/product-icon-badge/tags/1.2.4/ns_IBA_mainOptions/ns_addNewOptionsPage.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d1c1847c-8cc9-4080-8da5-7364c4358034?source=cve