Vulnerabilities / Pinterest for WooCommerce / WPSEC-2026-0661
Pinterest for WooCommerce <= 1.5.1 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via Settings REST Endpoint
Medium 5.5
CWE-79Fixed in 1.5.2
- ID
- WPSEC-2026-0661
- Plugin
- Pinterest for WooCommerce (pinterest-for-woocommerce)
- Affected
- from 1.2.5 before 1.5.2
- Remediation
- Update to 1.5.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Pinterest for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Pinterest for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 1.2.5 up to, and including, 1.5.1 due to the settings REST endpoint saving every submitted key, including server-owned Pinterest account data, and the catalog page rendering the stored ad credits value as HTML without sanitization. This makes it possible for authenticated attackers with shop manager-level access and above to inject arbitrary web scripts that execute whenever an administrator accesses the plugin's catalog page.
References
- https://wpsec.com/vuln/WPSEC-2026-0661/
- https://plugins.svn.wordpress.org/pinterest-for-woocommerce/tags/1.5.2/
- https://wordpress.org/plugins/pinterest-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS