plugin

Storegrowth Sales Booster Vulnerabilities

4 known security issues reported for the Storegrowth Sales Booster WordPress plugin. Most recent disclosed Aug 10, 2026.

1 high 3 medium

Running Storegrowth Sales Booster on your site? Check whether your installed version is affected.

Scan your site free

StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce <= 2.1.1 - Missing Authorization

medium

The StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to perform an unauthorized actio...

CVSS:
5.3
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Aug 10, 2026

CVE-2026-66466 on NVD →

StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter

high

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This ma...

CVSS:
7.2
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Jul 27, 2026

CVE-2026-13440 on NVD →

StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action

medium

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_ajax_nopriv_) users and...

CVSS:
5.3
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Jul 27, 2026

CVE-2026-13110 on NVD →

StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action

medium

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes...

CVSS:
5.3
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Jul 27, 2026

CVE-2026-15411 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database