Stored Cross-Site Scripting Vulnerability in StoreGrowth WooCommerce Plugin
CVE-2026-13440

7.2HIGH

What is CVE-2026-13440?

The StoreGrowth: Smart Sales Booster for WooCommerce plugin is susceptible to stored cross-site scripting due to inadequate input sanitization and output escaping in the 'message_popup' parameter. This vulnerability allows attackers, without authentication, to inject arbitrary scripts. The exploitation occurs because the required 'ajd_protected' nonce is exposed to all users through wp_localize_script, bypassing standard access controls. Consequently, whenever a user accesses an affected page, injected scripts may execute, posing severe security risks.

Affected Version(s)

StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce 0 <= 2.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chawabhon Netisingha (JNX03)
.