WPIntell

Source evidence

Cross Site Scripting vulnerability in plugin

Advanced Woo Labels – Product Labels & Badges for WooCommerce · support · 2025-04-08T16:53:00+00:00

mixedsentiment
highseverity
0.88relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 19 rows with source links

15.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
EvD resolved
Dear sir/madam, According to Patchstack.com your Woo Labels plugin has a cross site scripting vulnerability. Is that correct? If yes, when will there be an update available? Best, E Hi, According to Wordfence , the plugin is vulnerable to stored cross-site scripting (CSS). Is there an update planned to address this issue? Is that correct? If yes, when will there be an update available? Thank you, I look forward to a response. Hi, Before this I didn’t receive any email from Patchstack.com about this issue. From their report I see that it indeed has some vulnerability that was reported a few days ago. It has low priority status and low severity impact, but I’m still planning to release a new plugin version next week with a fix for this. Regards Good news – I just released a new plugin version with a fix for this. Excellent, thank you.

Comments

4 shown
megapublicidad 2025-04-09T10:21:00+00:00

Hi, According to Wordfence , the plugin is vulnerable to stored cross-site scripting (CSS). Is there an update planned to address this issue? Is that correct? If yes, when will there be an update available? Thank you, I look forward to a response.

ILLID 2025-04-09T11:00:00+00:00

Hi, Before this I didn’t receive any email from Patchstack.com about this issue. From their report I see that it indeed has some vulnerability that was reported a few days ago. It has low priority status and low severity impact, but I’m still planning to release a new plugin version next week with a fix for this. Regards

ILLID 2025-04-10T11:12:00+00:00

Good news – I just released a new plugin version with a fix for this.

EvD 2025-04-11T05:20:00+00:00

Excellent, thank you.