Stored Cross-Site Scripting Vulnerability in StoreGrowth WooCommerce Plugin
CVE-2026-13440
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-13440?
The StoreGrowth: Smart Sales Booster for WooCommerce plugin is susceptible to stored cross-site scripting due to inadequate input sanitization and output escaping in the 'message_popup' parameter. This vulnerability allows attackers, without authentication, to inject arbitrary scripts. The exploitation occurs because the required 'ajd_protected' nonce is exposed to all users through wp_localize_script, bypassing standard access controls. Consequently, whenever a user accesses an affected page, injected scripts may execute, posing severe security risks.
Affected Version(s)
StoreGrowth β Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce 0 <= 2.1.0