PT-2026-65445 · WordPress · Storegrowth: Smart Sales Booster For Woocommerce
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart versions prior to 2.1.1
Description
Stored Cross-Site Scripting (XSS) occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the affected page. The issue is facilitated by the exposure of the
ajd protected nonce required by the create popup() handler to all unauthenticated frontend visitors via wp localize script under bogo save url.ajd nonce, bypassing the nonce-only access control. The vulnerable parameter is message popup.Recommendations
Update StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart to a version newer than 2.1.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Storegrowth: Smart Sales Booster For Woocommerce