What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JC Custom Add to Cart Button Label and Link woo-custom-cart-button allows Stored XSS.This issue affects Custom Add to Cart Button Label and Link: from n/a through <= 1.6.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Custom Add to Cart Button Label and Link plugin for versions up to 1.6.1 contains a cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts through the plugin's settings. When another user views the affected page, the script executes in their browser, potentially stealing session data or performing actions on their behalf. The vulnerability requires user interaction and affects the site's integrity and confidentiality.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that executes when other users view the affected page, potentially stealing data or hijacking sessions.
Potential impact on your site
04Site Impact
Visitors' browsers can be compromised; attackers may steal session tokens, redirect users, or deface content without your knowledge.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege account (e.g., contributor or subscriber) and the victim must visit a page containing the vulnerable button.
Key dates
06Disclosure timeline
October 17, 2024
CVE published
April 28, 2026
Record updated