Sceawere

Vulnerability Detail

CVE-2026-39750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in StoreGrowth Plugin

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
weDevs
Product
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:46.487Z",
  "pubdate": "2026-10-06T09:17:46.487Z",
  "executiveSummary": "An unauthenticated Stored Cross-Site Scripting (XSS) vulnerability exists in the StoreGrowth: Smart Sales Booster for WooCommerce plugin, specifically affecting versions 2.0.6 and below.\nThe vulnerability arises from insufficient sanitization of user-supplied input before it is rendered within the administrative or storefront context.\nAn unauthenticated attacker can inject arbitrary malicious JavaScript into the application, which executes in the context of the victim's browser session upon accessing the affected page.\nSuccessful exploitation allows for complete compromise of the victim's session, including the theft of session cookies, administrative account takeover, unauthorized modification of site content, and potential redirection to malicious external domains.\nBecause this vulnerability does not require authentication, the attack surface is significantly exposed to any remote user browsing the WooCommerce store.\nOrganizations using this plugin are at critical risk of cross-site attacks targeting both administrators and end-users, potentially leading to unauthorized data exfiltration or site-wide malware distribution.",
  "technicalDetails": "The vulnerability is categorized as a Stored Cross-Site Scripting (XSS) flaw. It stems from the plugin's failure to adequately sanitize and escape user-supplied data transmitted via HTTP requests, which is subsequently persisted to the database and reflected in the front-end or administrative dashboard.\nThe root cause lies in the improper handling of input fields that the StoreGrowth plugin processes during its direct checkout or side cart operations. When an attacker submits crafted, malicious payloads into these input parameters, the plugin stores the input without performing server-side validation or output encoding.\nThe attack flow initiates when an unauthenticated actor sends a specially crafted POST request to the server, incorporating script tags or event handlers (e.g., <script>alert(document.cookie)</script> or onmouseover events) into the vulnerable fields. Upon the application storing this input, the payload becomes resident within the WooCommerce database.\nWhenever a legitimate user or administrator navigates to the affected component (such as the quick view, side cart, or checkout view), the application retrieves the malicious input from the database and renders it directly into the HTML Document Object Model (DOM) without context-aware output encoding.\nThe browser interprets the injected data as legitimate executable code rather than plain text, triggering the JavaScript execution in the context of the victim's session. This bypasses Same-Origin Policy (SOP) protections, allowing the malicious script to access sensitive information such as LocalStorage, SessionStorage, and session cookies.\nThis vulnerability is particularly severe because it requires zero authentication, meaning the attacker does not need prior access to the WordPress dashboard or a customer account. The scope of impact is broad, as any user interacting with the compromised checkout or cart flows becomes a potential victim, facilitating targeted phishing, unauthorized administrative actions, or the deployment of web skimmers (Magecart-style attacks) to harvest customer payment data during the checkout process."
}
CVE-2026-39750: Unauthenticated XSS in StoreGrowth Plugin (HIGH Severity, CVSS: 7.1) | Sceawere