PatchSiren cyber security CVE debrief
CVE-2026-15662 mihail-barinov CVE debrief
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject web scripts that execute when users access injected pages. The vulnerability exists due to insufficient input sanitization and output escaping in the 'bg_color' parameter. The Advanced Woo Labels plugin for WordPress is widely used for adding product labels and badges, making it a potential target for attackers. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then. The NVD provides additional details on the vulnerability, including its severity and potential impact.
- Vendor
- mihail-barinov
- Product
- Advanced Woo Labels – Product Labels & Badges for WooCommerce
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
WordPress site administrators and users with contributor-level access should be aware of this vulnerability and take necessary actions to protect their sites. They should verify the Advanced Woo Labels plugin version, restrict contributor-level access, and monitor for suspicious activity on WooCommerce pages. Additionally, they should implement additional security measures for WordPress sites and review compensating controls for exposed systems.
Technical summary
The Advanced Woo Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48. The vulnerability exists due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access to inject web scripts. These scripts can execute when users access injected pages, potentially leading to unauthorized actions or data breaches. The plugin's vulnerability is particularly concerning for WordPress site administrators and users with contributor-level access, as it can be exploited to inject malicious scripts. The vulnerability has been assigned a CVSS score of 6.4, indicating a medium severity level.
Defensive priority
Authenticated attackers with contributor-level access can inject web scripts that execute when users access injected pages.
Recommended defensive actions
- Inventory and verify the Advanced Woo Labels plugin version.
- Restrict contributor-level access and above.
- Monitor for suspicious activity on WooCommerce pages.
- Implement additional security measures for WordPress sites.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access can inject web scripts that execute when users access injected pages. The vulnerability exists in the Advanced Woo Labels plugin due to insufficient input sanitization and output escaping. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then. The NVD provides additional details on the vulnerability.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then.