Impact
The Brands for WooCommerce plugin stores user‑supplied content in the private field 'br_brand_tooltip' without adequate sanitization or output escaping. This is a classic CWE‑79 cross‑site scripting weakness that allows an authenticated attacker who holds at least Shop Manager privileges to inject arbitrary JavaScript that is later executed in the browsers of any visitor who views a page rendering the term meta. The stored payload bypasses the WordPress unfiltered_html capability exception that normally protects Shop Manager users, enabling the attacker to compromise site integrity and potentially steal credentials, hijack sessions, or deface content.
Affected Systems
All WordPress installations that use the Berocket Brands for WooCommerce plugin, versions 3.8.8 and earlier, are affected.
Risk and Exploitability
The CVSS v3.1 score of 4.4 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid user account with Shop Manager or higher privileges; once a malicious payload is stored in the 'br_brand_tooltip' field, every user who views the affected page will execute it in their browser. While the attack surface is restricted to authenticated users, the potential impact to confidentiality, integrity, and availability of the site warrants prompt attention.
OpenCVE Enrichment