Pinterest for WooCommerce <= 1.5.1 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via Settings REST Endpoint

Medium 5.5 CWE-79Fixed in 1.5.2
ID
WPSEC-2026-0661
Plugin
Pinterest for WooCommerce (pinterest-for-woocommerce)
Affected
from 1.2.5 before 1.5.2
Remediation
Update to 1.5.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Pinterest for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Pinterest for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 1.2.5 up to, and including, 1.5.1 due to the settings REST endpoint saving every submitted key, including server-owned Pinterest account data, and the catalog page rendering the stored ad credits value as HTML without sanitization. This makes it possible for authenticated attackers with shop manager-level access and above to inject arbitrary web scripts that execute whenever an administrator accesses the plugin's catalog page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0