WordPress · Storegrowth: Smart Sales Booster For Woocommerce · CVE-2026-13440
**Name of the Vulnerable Software and Affected Versions**
StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart versions prior to 2.1.1
**Description**
Stored Cross-Site Scripting (XSS) occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user accesses the affected page. The issue is facilitated by the exposure of the `ajd protected` nonce required by the `create popup()` handler to all unauthenticated frontend visitors via `wp localize script` under `bogo save url.ajd nonce`, bypassing the nonce-only access control. The vulnerable parameter is `message popup`.
**Recommendations**
Update StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart to a version newer than 2.1.0.