CVE detail
CVE-2026-15647
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unfiltered_html capability exception does not apply, meaning Shop Manager-level users — who normally lack unfiltered_html — can fully exploit this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/89f6fa65-ef71-491e-8959-591b58d1444c?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3608899%40brands-for-woocommerce&new=3608899%40brands-for-woocommerceplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/main.php#L774plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM - https://plugins.trac.wordpress.org/browser/brands-for-woocommerce/tags/3.8.8/main.php#L718plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 23, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-15730CVSS 6.4 · Medium
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size…
- CVE-2026-17528CVSS 5.3 · Medium
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendere…
- CVE-2026-65448CVSS 6.5 · Medium
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.
- CVE-2026-65447CVSS 7.1 · High
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
- CVE-2026-65446CVSS 7.1 · High
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
- CVE-2026-65443CVSS 7.1 · High
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.