Sceawere
Vulnerability Detail
CVE-2026-105056UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in eCommerce Product Catalog
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 10h ago
- Vendor
- impleCode
- Product
- eCommerce Product Catalog
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T09:17:10.727Z",
"pubdate": "2026-10-05T09:17:10.727Z",
"executiveSummary": "The eCommerce Product Catalog plugin for WordPress, specifically versions 3.6.2 and earlier, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability arises from the improper neutralization of user-supplied input during web page generation.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject and persist malicious JavaScript payloads within the web application.\nWhen a victim, such as an administrator or end-user, views the affected page, the malicious script executes within their browser session.\nThe risk implications include unauthorized access to sensitive user data, session hijacking, defacement of the web catalog, and potential redirection to malicious external domains.\nThis vulnerability highlights a failure in input validation and output encoding mechanisms, granting attackers the capability to perform actions on behalf of the victim under the security context of the vulnerable application.",
"technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nThe root cause of this vulnerability lies in the insufficient sanitization or improper escaping of user-provided data before it is persisted in the database and subsequently rendered in the browser. Within the eCommerce Product Catalog architecture, input fields intended for product metadata or catalog configuration likely lack robust server-side validation or context-aware output encoding.\nThe exploitation flow begins when an attacker identifies a vulnerable input field, such as product names, descriptions, or specific configuration parameters. The attacker injects a malicious script payload (e.g., <script>alert(document.cookie)</script>) into the input field, which the application subsequently stores in the database without performing the necessary character entity encoding or stripping of dangerous tags.\nThe attack is persistent (Stored XSS) because the payload is stored directly on the server. Whenever a legitimate user or administrator navigates to the affected page, the server retrieves the compromised data and renders the payload as active HTML/JavaScript content within the response document. The victim's browser, lacking instructions to treat the data as plain text, executes the injected script with the privileges of the victim's current session.\nImpact analysis indicates that upon successful execution, the injected script can access session cookies, perform unauthorized API requests, capture keystrokes, or exfiltrate sensitive information stored in the Document Object Model (DOM). Because the script executes within the context of the trusted domain, it effectively bypasses Same-Origin Policy (SOP) restrictions related to the storage and retrieval of data from the application.\nAffected versions are identified as any version from n/a through 3.6.2. The vulnerability does not specify complex exploitation requirements, as the attack relies on standard application functionalities for data input and display. If the vulnerable input vector is accessible to public users, the attack may be carried out by an unauthenticated attacker, whereas other vectors may require specific administrative or user-level privileges to inject the payload.\nPost-exploitation scenarios include the unauthorized escalation of privileges if an administrator visits the compromised page, potentially leading to a complete compromise of the WordPress environment."
}