CVE-2026-15647 MEDIUM

CVE-2026-15647: Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field

Vendor Berocket
Product Brands for WooCommerce
Weakness CWE-79 · XSS
Published July 23, 2026
Last update July 23, 2026

CVSS base score

4.4/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.

Explanation of Vulnerability in Simple Terms

02Summary

Brands for WooCommerce versions 3.8.8 and earlier contain a cross-site scripting vulnerability that allows high-privilege users to inject malicious scripts affecting other users or the site. The vulnerability requires high attack complexity and administrative access to exploit. Impact is limited to low-level confidentiality and integrity compromise.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that affect other users or site functionality.

Potential impact on your site

04Site Impact

A compromised admin account could inject scripts affecting other users or site behavior.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges on the WooCommerce site.

Key dates

06Disclosure timeline

July 23, 2026 CVE published

Related vulnerabilities

08Related CVE