What the vulnerability does
01Description
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.
Explanation of Vulnerability in Simple Terms
02Summary
Brands for WooCommerce versions 3.8.8 and earlier contain a cross-site scripting vulnerability that allows high-privilege users to inject malicious scripts affecting other users or the site. The vulnerability requires high attack complexity and administrative access to exploit. Impact is limited to low-level confidentiality and integrity compromise.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that affect other users or site functionality.
Potential impact on your site
04Site Impact
A compromised admin account could inject scripts affecting other users or site behavior.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the WooCommerce site.
Key dates
06Disclosure timeline
July 23, 2026
CVE published