MEDIUM
mihail-barinov
CVE published 2026-08-01
CVE-2026-15662
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bg_color' parameter in all versions up to, and including, 2.48 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject web scripts that execute when users access injected pa [truncated]