CVE-2026-81282: WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Product Variations Swatches for WooCommerceto a version that resolves this vulnerability.Fixed in 1.1.19
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a Subscriber-level account on a WordPress site using the affected plugin. Exploitation also requires a user to interact with the attacker-supplied content.
What impact can successful exploitation have?
The vulnerability is cross-site scripting and is rated medium severity with low confidentiality, integrity, and availability impact. Its scope is changed, indicating the impact can extend beyond the vulnerable component.
Which plugin versions are affected?
Product Variations Swatches for WooCommerce versions 1.1.18 and earlier are identified as affected.