Stored Cross-Site Scripting Vulnerability in Brands for WooCommerce Plugin by WordPress
CVE-2026-15647
4.4MEDIUM
What is CVE-2026-15647?
The Brands for WooCommerce plugin for WordPress contains a vulnerability that allows authenticated attackers to perform stored cross-site scripting (XSS) through the 'br_brand_tooltip' Term Meta Field. This security flaw arises from inadequate input sanitization and output escaping, permitting attackers with custom-level access or higher to inject arbitrary web scripts. The malicious payload is stored in the term meta data instead of the post content, effectively bypassing standard WordPress restrictions, thus enabling even Shop Manager-level users to exploit this vulnerability, posing significant risks to site integrity and user security.
Affected Version(s)
Brands for WooCommerce 0 <= 3.8.8