CVE-2026-7436

WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 244 live websites that are affected by CVE-2026-7436.

Run a Free Instant Scan




Affected Software

Product  Wpc Badge Management
Category Wordpress Plugins
Vulnerable Domains244 live websites (48% of Wpc Badge Management install base)
Vulnerable Versions
  • from 0 through 3.1.6
Vulnerable Versions Count20 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 29, 2026
  • Updated - Jul 29, 2026

Credits

  • zaim (finder)

Website Distribution by Country

Number of websites using CVE-2026-7436
United States31 websites



Italy22 websites
France22 websites
Germany17 websites
Greece11 websites
Romania10 websites
Russia9 websites
Poland9 websites
Belgium8 websites
Hungary5 websites

Website Distribution by TLD

Number of websites using CVE-2026-7436
.com69 websites
.it16 websites
.pl9 websites
.fr9 websites
.ru8 websites
.de6 websites
.co.uk5 websites
.com.br5 websites
.se4 websites
.ch3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-7436

Top websites that are affected by CVE-2026-7436. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States*,***,***
**********.com Austria*,***,***
****.************.net Italy*,***,***
*****.********.pl Poland*,***,***
*************.***.au Australia*,***,***
*********.com United States*,***,***
********.**.za South Africa*,***,***
*************.com France*,***,***
**********.es France*,***,***
******.it Italy*,***,***
See full domain list

FAQ

CVE-2026-7436 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wpc Badge Management
A total of 244 websites have been identified as vulnerable to CVE-2026-7436, based on global website indexing conducted by WebTechSurvey.
The Wpc Badge Management is affected by the CVE-2026-7436 vulnerability.
Wpc Badge Management versions up to and including 3.1.6 are vulnerable to CVE-2026-7436.