Reflected Cross-Site Scripting Vulnerability in SysBasics Customize My Account for WooCommerce
CVE-2026-12137
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-12137?
The SysBasics Customize My Account for WooCommerce plugin for WordPress is susceptible to reflected cross-site scripting via the 'tab' parameter in all versions up to and including 4.3.6. This vulnerability arises from inadequate input sanitization and output escaping. Attackers can exploit this issue by injecting arbitrary web scripts into pages, executing them when a user is tricked into performing an action, such as clicking a malicious link. Successful exploitation requires the victim to be logged into the WordPress admin dashboard with Shop Manager-level access or higher, making unauthorized access a critical concern for users managing their online stores.
Affected Version(s)
SysBasics Customize My Account for WooCommerce β Dashboard, Endpoints, Avatar & Menu Manager 0 <= 4.3.6