Description
The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-05-13
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin, allowing authenticated users with contributor-level access or higher to inject arbitrary scripts via the shortcodes 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit'. This stored cross‑site scripting flaw stems from inadequate input sanitization and output escaping, and the injected scripts execute whenever a visitor accesses a page containing the malicious shortcode. The weakness is identified as CWE‑79, which permits attackers to compromise user browsers, potentially stealing credentials, session data, or installing malware. The impact is confined to the web interface of the affected site and does not provide direct code execution on the server.

Affected Systems

The plugin "Cost of Goods: Product Cost & Profit Calculator for WooCommerce" by wpcodefactory is affected in all releases up to and including version 4.1.0. Users must verify the plugin version installed on the WordPress instance and note that contributor‑level or higher accounts are required to exploit the flaw.

Risk and Exploitability

The CVSS score of 6.4 categorizes this vulnerability as medium severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog, indicating no currently known mass exploitation. The attack vector is inferred to be an authenticated contributor with the ability to edit products or settings, who can insert malicious attributes into the shortcodes. Once injected, the malicious scripts will run in the context of any user who views the affected page, providing a persistent cross‑site scripting vector across site visitors.

Generated by OpenCVE AI on May 13, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version newer than 4.1.0, which includes proper input validation and output escaping.
  • If an immediate update cannot be performed, limit the contributor role to trusted users and audit any product or settings pages for unexpected code injection.
  • Apply content‑security‑policy headers to the site to restrict execution of inline scripts and mitigate accidental script execution from the vulnerable plugin.

Generated by OpenCVE AI on May 13, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpcodefactory
Wpcodefactory cost Of Goods: Product Cost & Profit Calculator For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpcodefactory
Wpcodefactory cost Of Goods: Product Cost & Profit Calculator For Woocommerce

Wed, 13 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Cost of Goods: Product Cost & Profit Calculator for WooCommerce <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpcodefactory Cost Of Goods: Product Cost & Profit Calculator For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-13T10:22:24.831Z

Reserved: 2026-04-24T15:42:12.086Z

Link: CVE-2026-6962

cve-icon Vulnrichment

Updated: 2026-05-13T10:18:54.002Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T05:16:24.213

Modified: 2026-05-13T14:43:46.717

Link: CVE-2026-6962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:34:52Z

Weaknesses