Cross Site Scripting Vulnerability in Product Variations Swatches for WooCommerce
CVE-2026-81282
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-81282?
A cross site scripting (XSS) vulnerability exists in the Product Variations Swatches for WooCommerce plugin affecting versions up to 1.1.18. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions such as data theft and user impersonation. Web administrators are advised to update the plugin immediately to mitigate the risks associated with this vulnerability.
Affected Version(s)
Product Variations Swatches for WooCommerce <= 1.1.18