The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 202 live websites that are affected by CVE-2026-15324.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 202 live websites (93% of Customize My Account For Woocommerce install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 18 versions ( 90% of all versions) |
| 72 websites | |
| 20 websites | |
| 10 websites | |
| 10 websites | |
| 8 websites | |
| 7 websites | |
| 6 websites | |
| 6 websites | |
| 5 websites | |
| 5 websites |
| .com | 101 websites |
| .de | 12 websites |
| .net | 10 websites |
| .org | 8 websites |
| .nl | 6 websites |
| .com.br | 5 websites |
| .it | 4 websites |
| .ch | 4 websites |
| .ru | 3 websites |
| .ca | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | ***,*** | ||
| ***********.de | ***,*** | ||
| *****.com | ***,*** | ||
| ******.org | ***,*** | ||
| ***********.com | ***,*** | ||
| *******************.com | ***,*** | ||
| ******.ru | ***,*** | ||
| ***************.com | ***,*** | ||
| *********.ch | ***,*** | ||
| *.***********.com | ***,*** |
FAQ