# WooCommerce EU VAT Assistant <= 2.1.30.260413 - Unauthenticated Stored Cross-Site Scripting via VAT Number

- **ID:** WPSEC-2026-0472
- **Plugin:** EU VAT Assistant for WooCommerce (`woocommerce-eu-vat-assistant`), https://wordpress.org/plugins/woocommerce-eu-vat-assistant/
- **Affected versions:** all versions before 2.2.0.261001
- **Fixed in:** 2.2.0.261001 (Update to 2.2.0.261001 or later.)
- **Severity:** High 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-eu-vat-assistant
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0472/

## Description

The EU VAT Assistant for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the VAT number submitted at checkout in all versions up to, and including, 2.1.30.260413 due to insufficient input sanitization of the VAT number and missing output escaping of VAT evidence values in the admin order meta box. This makes it possible for unauthenticated attackers, such as guest customers placing an order, to inject arbitrary web scripts that will execute whenever an administrator or shop manager views the affected order.

## References

- https://wpsec.com/vuln/WPSEC-2026-0472/
- https://plugins.svn.wordpress.org/woocommerce-eu-vat-assistant/tags/2.2.0.261001/
- https://wordpress.org/plugins/woocommerce-eu-vat-assistant/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0472/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
