Security Brief: CVE-2026-12241 Advanced Woo Labels Flaw Enables Stored XSS https://vulnify.app/blog/security-brief-cve-2026-12241-advanced-woo-labels-stored-xss CVE-2026-12241 is a medium-severity stored cross-site scripting vulnerability affecting Advanced Woo Labels for WooCommerce through version 2.51. Authenticated users with Contributor-level access or higher can create label content that is rendered without adequate escaping. What happened CVE-2026-12241 is a medium-severity stored cross-site scripting vulnerability in Advanced Woo Labels – Product Labels & Badges for WooCommerce. According to the NVD record supplied by Wordfence, versions through 2.51 are affected. The issue stems from an insufficient capability check in save_meta_boxes , allowing authenticated users with Contributor-level access or higher to create label content that can be rendered without adequate escaping. Wordfence assigns CVSS 3.1 score 5.4 and classifies the weakness as CWE-79. Version 2.46 only partially addressed the problem. The plugin changelog shows version 2.52 added escaping for custom CSS options, making 2.52 the first release outside the published affected range. Version 2.53 is now available, so sites should normally update to the latest supported release rather than stopping at the minimum fix. Why it matters for website owners This vulnerability requires an authenticated low-privileged account, so it is not an unauthenticated takeover flaw. The risk is that attacker-controlled label data can persist in WordPress and later execute in the browser of another user when the affected output is rendered. Depending on where that content appears, stored XSS can be used to interfere with administrative actions, alter displayed content, or access data available to the victim's browser session. What to check on your site Confirm whether Advanced Woo Labels is installed and update any version through 2.51 to 2.52 or later, preferably the current supported release. Review Contributor, Author, Editor, and Administrator accounts for users who should no longer have access. Inspect recently created or modified WooCommerce labels and custom CSS values for unexpected content. Use the WordPress Stack Checker to review publicly detectable WordPress technology, while confirming plugin versions directly inside WordPress. Related reading WordPress Security Hardening Checklist WordPress Stack Checker Sources NIST NVD: CVE-2026-12241 WordPress.org: Advanced Woo Labels