PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15662 mihail-barinov CVE debrief

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject web scripts that execute when users access injected pages. The vulnerability exists due to insufficient input sanitization and output escaping in the 'bg_color' parameter. The Advanced Woo Labels plugin for WordPress is widely used for adding product labels and badges, making it a potential target for attackers. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then. The NVD provides additional details on the vulnerability, including its severity and potential impact.

Vendor
mihail-barinov
Product
Advanced Woo Labels – Product Labels & Badges for WooCommerce
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

WordPress site administrators and users with contributor-level access should be aware of this vulnerability and take necessary actions to protect their sites. They should verify the Advanced Woo Labels plugin version, restrict contributor-level access, and monitor for suspicious activity on WooCommerce pages. Additionally, they should implement additional security measures for WordPress sites and review compensating controls for exposed systems.

Technical summary

The Advanced Woo Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48. The vulnerability exists due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access to inject web scripts. These scripts can execute when users access injected pages, potentially leading to unauthorized actions or data breaches. The plugin's vulnerability is particularly concerning for WordPress site administrators and users with contributor-level access, as it can be exploited to inject malicious scripts. The vulnerability has been assigned a CVSS score of 6.4, indicating a medium severity level.

Defensive priority

Authenticated attackers with contributor-level access can inject web scripts that execute when users access injected pages.

Recommended defensive actions

  • Inventory and verify the Advanced Woo Labels plugin version.
  • Restrict contributor-level access and above.
  • Monitor for suspicious activity on WooCommerce pages.
  • Implement additional security measures for WordPress sites.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access can inject web scripts that execute when users access injected pages. The vulnerability exists in the Advanced Woo Labels plugin due to insufficient input sanitization and output escaping. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then. The NVD provides additional details on the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:16:59.737Z and has not been modified since then.