Vulnerabilities / WooCommerce EU VAT Assistant / WPSEC-2026-0472
WooCommerce EU VAT Assistant <= 2.1.30.260413 - Unauthenticated Stored Cross-Site Scripting via VAT Number
High 7.2
CWE-79Fixed in 2.2.0.261001
- ID
- WPSEC-2026-0472
- Plugin
- EU VAT Assistant for WooCommerce (woocommerce-eu-vat-assistant)
- Affected
- all versions before 2.2.0.261001
- Remediation
- Update to 2.2.0.261001 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- WooCommerce EU VAT Assistant on WPSec AttackSurface
- Fix released
- Published
Description
The EU VAT Assistant for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the VAT number submitted at checkout in all versions up to, and including, 2.1.30.260413 due to insufficient input sanitization of the VAT number and missing output escaping of VAT evidence values in the admin order meta box. This makes it possible for unauthenticated attackers, such as guest customers placing an order, to inject arbitrary web scripts that will execute whenever an administrator or shop manager views the affected order.
References
- https://wpsec.com/vuln/WPSEC-2026-0472/
- https://plugins.svn.wordpress.org/woocommerce-eu-vat-assistant/tags/2.2.0.261001/
- https://wordpress.org/plugins/woocommerce-eu-vat-assistant/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS