WordPress Plugin Vulnerabilities

Product Table & List Builder For WooCommerce < 5.6.5 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter

Description

The plugin is vulnerable to CSS Injection via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenticated wcpt_ajax() AJAX handler. The handler is registered for wp_ajax_nopriv_wcpt_ajax, JSON-decodes attacker-supplied attributes, only allowlists key names (not values), applies a preg_replace that strips only [ ] < >, and passes the value through do_shortcode into wcpt_style__sticky_sidebar(), where it is interpolated verbatim into inline CSS ('top: {$top}px;' and 'max-height: calc(100vh - {$top}px);') with no numeric casting or CSS escaping. This makes it possible for unauthenticated attackers to inject arbitrary CSS declarations and rules on pages rendering a product table with sticky sidebar enabled, which can be leveraged for data exfiltration (via attribute-selector + background-image URLs), UI redressing, and phishing that bypasses CSPs permitting inline styles.

Affects Plugins

References

Classification

Type
CONTENT INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
Wordfence PRISM
Verified
No

Timeline

Publicly Published
2026-08-15 (about 9 days ago)
Added
2026-08-17 (about 6 days ago)
Last Updated
2026-08-17 (about 6 days ago)

Other