HIGH
Anton Bond
CVE published 2026-10-10
CVE-2026-39800
Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce plugin versions up to 1.24 allows attackers to inject malicious scripts into web pages viewed by unauthenticated users, potentially leading to site integrity impacts and user data exposure. Defenders should verify exposure and apply patches due to the HIGH severity CVSS score of 7.1. The CVE record and NVD entry provide [truncated]