What is CVE-2026-16597?
CVE-2026-16597 affects the 'GTM4WP' WordPress plugin, allowing Stored XSS via WooCommerce Billing Fields due to insufficient input sanitization and output escaping. Users should update to a patched version immediately.
Azərbaycanca: CVE-2026-16597 WordPress üçün 'GTM4WP' plaginində aşkarlanıb. Bu boşluq WooCommerce hesab məlumatları sahələrində saxlanılan XSS hücumlarına imkan verir, çünki daxiletmə təmizlənməsi və çıxış qaçırılması yetərsizdir. Plagin istifadəçiləri ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-16597?
CVE-2026-16597 affects the 'GTM4WP' plugin.
What type of security issue does CVE-2026-16597 cause?
This vulnerability allows Stored XSS attacks via WooCommerce Billing Fields.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.