Stored Cross-Site Scripting Vulnerability in Brands for WooCommerce Plugin by WordPress
CVE-2026-15647

4.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-15647?

The Brands for WooCommerce plugin for WordPress contains a vulnerability that allows authenticated attackers to perform stored cross-site scripting (XSS) through the 'br_brand_tooltip' Term Meta Field. This security flaw arises from inadequate input sanitization and output escaping, permitting attackers with custom-level access or higher to inject arbitrary web scripts. The malicious payload is stored in the term meta data instead of the post content, effectively bypassing standard WordPress restrictions, thus enabling even Shop Manager-level users to exploit this vulnerability, posing significant risks to site integrity and user security.

Affected Version(s)

Brands for WooCommerce 0 <= 3.8.8

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.