WooCommerce EU VAT Assistant <= 2.1.30.260413 - Unauthenticated Stored Cross-Site Scripting via VAT Number

High 7.2 CWE-79Fixed in 2.2.0.261001
ID
WPSEC-2026-0472
Plugin
EU VAT Assistant for WooCommerce (woocommerce-eu-vat-assistant)
Affected
all versions before 2.2.0.261001
Remediation
Update to 2.2.0.261001 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
WooCommerce EU VAT Assistant on WPSec AttackSurface
Fix released
Published

Description

The EU VAT Assistant for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the VAT number submitted at checkout in all versions up to, and including, 2.1.30.260413 due to insufficient input sanitization of the VAT number and missing output escaping of VAT evidence values in the admin order meta box. This makes it possible for unauthenticated attackers, such as guest customers placing an order, to inject arbitrary web scripts that will execute whenever an administrator or shop manager views the affected order.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0