Stored Cross-Site Scripting Vulnerability in WPC Badge Management for WooCommerce Plugin
CVE-2026-7436
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-7436?
The WPC Badge Management for WooCommerce plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping concerning the 'text' attribute in the wpcbm_best_seller shortcode. This vulnerability allows authenticated users with Contributor-level access or higher to potentially inject malicious scripts into web pages, which would execute when other users access those pages. This poses a significant security risk for websites utilizing this plugin, as it can compromise user data and lead to further exploits.
Affected Version(s)
WPC Badge Management for WooCommerce 0 <= 3.1.6