Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Bopo – WooCommerce Product Bundle Builder plugin processes user‑supplied data when generating product bundle pages. Because it does not properly neutralize input in the URL or form parameters, an attacker can inject arbitrary JavaScript that is reflected back into the browser. This is a classic reflected XSS flaw, classified as CWE‑79, and it enables the execution of malicious scripts, potentially leading to cookie theft, session hijacking, phishing, or defacement.

Affected Systems

Every WordPress site that has installed VillaTheme's Bopo – WooCommerce Product Bundle Builder plugin with a version number of 1.2.0 or earlier is vulnerable. The issue applies from the earliest available release up to and including 1.2.0, affecting all sites that have not upgraded beyond this version threshold.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but still present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through unauthenticated users who submit crafted URLs or form data containing malicious code; once a visitor loads the affected page, the script executes in the victim’s browser. No privileged access is required for exploitation.

Generated by OpenCVE AI on July 29, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bopo – WooCommerce Product Bundle Builder plugin to a version newer than 1.2.0 to apply the official fix.
  • If an upgrade is not feasible at this time, disable or remove the plugin to eliminate the vulnerability from the site.
  • As a temporary measure, configure the web application firewall to block or sanitize user‑supplied script tags or characters from reflected responses.

Generated by OpenCVE AI on July 29, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Villatheme
Villatheme bopo – Woocommerce Product Bundle Builder
Wordpress
Wordpress wordpress
Vendors & Products Villatheme
Villatheme bopo – Woocommerce Product Bundle Builder
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.
Title WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Villatheme Bopo – Woocommerce Product Bundle Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:43:11.695Z

Reserved: 2026-06-24T12:46:44.604Z

Link: CVE-2026-57422

cve-icon Vulnrichment

Updated: 2026-07-13T13:43:07.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T08:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')