Stored Cross-Site Scripting Vulnerability in Advanced Woo Labels Plugin for WordPress
CVE-2026-15662
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-15662?
The Advanced Woo Labels β Product Labels & Badges for WooCommerce WordPress plugin contains a vulnerability that enables authenticated users with contributor-level access and above to perform stored cross-site scripting. This occurs through the 'bg_color' parameter, where the plugin fails to properly sanitize and escape user input. As a result, attackers can inject malicious scripts into the web pages, which will execute when other users visit these pages, compromising user data and site integrity.
Affected Version(s)
Advanced Woo Labels β Product Labels & Badges for WooCommerce 0 <= 2.48