Impact
The vulnerability resides in the Brands for WooCommerce WordPress plugin and enables stored cross‑site scripting via the 'width' attribute of a shortcode. Insufficient sanitization and escaping of this attribute means that an attacker can embed malicious scripts that will run whenever a page containing the shortcode is viewed. Such scripts can steal user cookies, deface content, or propagate further attacks. The weakness is identified as CWE‑79, and the impact is limited to accounts with contributor‑level access or higher, which can place arbitrary content into the site and expose other visitors to execution of the injected code.
Affected Systems
Any installation of the Brands for WooCommerce plugin for WordPress where the version is 3.8.8 or earlier. The CNA vendor is berocket and the exposed product is the Brands for WooCommerce plugin. Users facing these versions must verify their plugin installation and plan remediation.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is listed as <1%, which shows a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild. The attack requires authentication with contributor or higher privileges, so an attacker must compromise a user account with sufficient role. Once authenticated, they can inject the payload, store it, and affect any user who views the affected page. The combination of authentication requirement, moderate CVSS, and low EPSS points to moderate overall risk, though the potential for damage from the injected scripts remains high.
OpenCVE Enrichment