WordPress Plugin Vulnerabilities

Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content

Description

The plugin does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
J4ck13Ch4n
Submitter
J4ck13Ch4n
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-22 (about 9 days ago)
Last Updated
2026-09-22 (about 9 days ago)

Other