CVE-2026-16597
Received Received - Intake

Stored XSS in GTM4WP WordPress Plugin via WooCommerce Billing

Vulnerability report for CVE-2026-16597, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: Wordfence

Description

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the GTM4WP WooCommerce order data integration option (GTM4WP_OPTION_INTEGRATE_WCORDERDATA) to be enabled, and is exploited by placing a guest checkout order with a JavaScript payload in a WooCommerce billing field such as the billing first name.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gtm4wp gtm4wp to 1.22.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the GTM4WP WordPress plugin up to version 1.22.3. It allows unauthenticated attackers to inject malicious scripts into WooCommerce billing fields via insufficient input sanitization and output escaping. The attack requires the GTM4WP WooCommerce order data integration option to be enabled.

Detection Guidance

Check if the GTM4WP plugin is installed and verify its version is below or equal to 1.22.3. Inspect WooCommerce billing fields for unusual JavaScript payloads in guest checkout orders. Enable logging for suspicious input in billing fields.

Impact Analysis

Unauthenticated attackers could inject malicious scripts into pages that execute when users access them. This could lead to theft of user sessions, defacement of pages, or delivery of malware to visitors. The impact depends on the privileges of users visiting the compromised pages.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. It may result in data breaches, unauthorized data exposure, and non-compliance with security and privacy controls.

Mitigation Strategies

Update the GTM4WP plugin to the latest version. Disable the GTM4WP WooCommerce order data integration option if not needed. Sanitize input in WooCommerce billing fields and implement strict output escaping. Monitor for unauthorized script injections in guest checkout orders.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart