What is CVE-2026-7436?
CVE-2026-7436 is a Stored Cross-Site Scripting vulnerability in the WPC Badge Management for WooCommerce plugin (up to version 3.1.6) via the 'text' attribute of the `wpcbm_best_seller` shortcode, caused by insufficient input sanitization and output escaping. Authenticated attackers can inject malicious scripts, and updating to the latest patched version is recommended.
Azərbaycanca: CVE-2026-7436, WooCommerce üçün WPC Badge Management plaginində (3.1.6-ya qədər versiyalar) `wpcbm_best_seller` shortcode-unun 'text' atributunda saxlanılan XSS zəifliyidir. Bu, yetərsiz sanitarizəyə görə autentifikasiyalı istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Plaqini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which function of the WPC Badge Management plugin does CVE-2026-7436 exist?
CVE-2026-7436 is a Stored XSS vulnerability that exists in the 'text' attribute of the `wpcbm_best_seller` shortcode.
What version of the WPC Badge Management plugin should be installed to protect against CVE-2026-7436?
Versions up to 3.1.6 are vulnerable, so updating to the latest patched version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.