Stored Cross-Site Scripting in GTM4WP WordPress Plugin
CVE-2026-16597
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-16597?
The GTM4WP plugin for WordPress is susceptible to a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping. This flaw allows unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields, specifically when the GTM4WP option for WooCommerce order data integration is active. By submitting a guest checkout order containing malicious JavaScript in a billing field (e.g., billing first name), the injected scripts will execute whenever the page is accessed by users, potentially leading to unauthorized access or data manipulation.
Affected Version(s)
GTM4WP β A Google Tag Manager (GTM) plugin for WordPress 0 <= 1.22.3