Stored Cross-Site Scripting in GTM4WP WordPress Plugin
CVE-2026-16597

7.2HIGH

What is CVE-2026-16597?

The GTM4WP plugin for WordPress is susceptible to a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping. This flaw allows unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields, specifically when the GTM4WP option for WooCommerce order data integration is active. By submitting a guest checkout order containing malicious JavaScript in a billing field (e.g., billing first name), the injected scripts will execute whenever the page is accessed by users, potentially leading to unauthorized access or data manipulation.

Affected Version(s)

GTM4WP – A Google Tag Manager (GTM) plugin for WordPress 0 <= 1.22.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lhking
.