← WordPress Vulnerabilities
WordPress security by component

Brands for WooCommerce

Brands for WooCommerce is a WordPress component with 6 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.5.

Plugin slug: brands-for-woocommerce

CVE-2026-15648: Brands for WooCommerce width shortcode attribute permits stored XSS

Brands for WooCommerce through 3.8.8 lets a Contributor store an attacker-controlled width attribute in the brands_product_thumbnail shortcode. brbrand_deprecated_shortcodes_divi_addon::description_post() concatenates that value into an image or span style attribute without validating the CSS size or escaping the completed attribute, allowing injected markup or script to execute when the post is rendered.

PublishedJul 24, 2026
Known safe version3.8.8.1
Safe version
Jul 24, 2026 CVE-2026-15648
Brands for WooCommerce width shortcode attribute permits stored XSS
Brands for WooCommerce through 3.8.8 lets a Contributor store an attacker-controlled width attribute in the brands_product_thumbnail shortcode. brbrand_deprecated_shortcodes_divi_addon::description_post() concatenates that value into an image or span style attribute without validating the CSS size or escaping the completed attribute, allowing injected markup or script to execute when the post is rendered.
3.8.8.1
CVE6.4
NVDPending
Jul 23, 2026 CVE-2026-15647
Brands for WooCommerce: Cross-site scripting
Brands for WooCommerce is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.8.8.
> 3.8.8
CVE4.4
NVDPending
Jul 23, 2026 CVE-2026-15646
Brands for WooCommerce: Cross-site scripting
Brands for WooCommerce is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.8.8.
> 3.8.8
CVE6.4
NVDPending
Dec 24, 2025 CVE-2025-68519
Brands for WooCommerce: SQL injection
Brands for WooCommerce is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Dec 13, 2024 CVE-2023-44149
Brands for WooCommerce: A security weakness
Brands for WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 18, 2023 CVE-2023-23667
Brands For Woocommerce: Cross-site scripting
Brands For Woocommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4