Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Bopo – WooCommerce Product Bundle Builder plugin contains an Improper Neutralization of Input During Web Page Generation vulnerability that permits reflected cross‑site scripting. User supplied data that is incorporated into URLs or form parameters is not correctly sanitized, leading to arbitrary code being reflected back to the client and executed in the victim’s browser.

Affected Systems

Any WordPress site that has installed VillaTheme’s Bopo – WooCommerce Product Bundle Builder plugin with a version number of 1.2.0 or earlier is affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while an EPSS score of less than 1 % suggests that exploitation is currently unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through unauthenticated users who send crafted URLs or form data to the site; the reflected input is executed without additional privileges.

Generated by OpenCVE AI on August 3, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bopo – WooCommerce Product Bundle Builder plugin to a version newer than 1.2.0 to apply the official fix.
  • If an upgrade is not feasible, disable or remove the plugin to eliminate the vulnerability from the site.
  • As a temporary measure, configure a web application firewall to block or sanitize script tags or characters that may appear in reflected responses.

Generated by OpenCVE AI on August 3, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme bopo – Woocommerce Product Bundle Builder
Wordpress
Wordpress wordpress
Vendors & Products Villatheme
Villatheme bopo – Woocommerce Product Bundle Builder
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.
Title WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Villatheme Bopo – Woocommerce Product Bundle Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:43:11.695Z

Reserved: 2026-06-24T12:46:44.604Z

Link: CVE-2026-57422

cve-icon Vulnrichment

Updated: 2026-07-13T13:43:07.616Z

cve-icon NVD

Status : Deferred

Published: 2026-07-13T10:16:36.200

Modified: 2026-07-13T16:57:56.050

Link: CVE-2026-57422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')