Sceawere

Vulnerability Detail

CVE-2026-13718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tabs Responsive Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
17h ago
Vendor
Unknown
Product
Tabs Responsive
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-02T06:16:40.123Z",
  "pubdate": "2026-10-02T06:16:40.123Z",
  "executiveSummary": "The Tabs Responsive WordPress plugin, in versions up to and including 2.5, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from inadequate input sanitization and output escaping mechanisms within the plugin's WooCommerce product tab handling functionality.\nThe vulnerability allows an authenticated user with 'shop manager' privileges to inject and store malicious JavaScript payloads within product tab content. Once saved, these scripts are executed in the browser of any user who views the affected product page, including high-privileged administrators.\nThe risk implication is significant, as successful exploitation enables session hijacking, unauthorized administrative actions, and potential site-wide compromise depending on the target's session privileges. Since the payload is stored persistently in the database, the attack does not require ongoing interaction from the malicious actor once the payload is injected. Exploitation is restricted to users with the capacity to manage WooCommerce products, limiting the initial vector to those with existing backend access.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS). The root cause is a failure of the plugin to implement robust input validation or output encoding on user-supplied content intended for WooCommerce product tabs. In WordPress, plugins that interact with post metadata or product fields must sanitize inputs using functions like sanitize_text_field() or wp_kses_post() and escape outputs using esc_html(), esc_attr(), or equivalent functions to prevent the execution of arbitrary code in the browser context.\nThe attack flow proceeds as follows: First, an authenticated attacker with 'shop manager' permissions accesses the product editing interface provided by the Tabs Responsive plugin. Second, the attacker inserts a malicious JavaScript payload (e.g., <script>alert(document.cookie)</script>) into one of the tab content fields. Third, the plugin processes the request and saves the unsanitized input directly into the WordPress database via the relevant meta-fields. Fourth, when a victim—such as a store administrator or an end-user—navigates to the WooCommerce product page, the plugin retrieves the stored, malicious string from the database and renders it directly into the HTML source code of the page without proper output escaping.\nBecause the payload is injected into the DOM, the browser executes the script automatically upon page load within the security context of the victim's session. This allows the attacker to perform actions on behalf of the victim, such as modifying administrative settings, creating new administrator accounts, or redirecting users to malicious external domains. Given that the payload is stored server-side, this represents a persistent security flaw that remains active until the malicious content is manually removed from the database or the vulnerable code is patched.\nThe attack vector is limited by the requirement of a 'shop manager' account, which is a high-privilege role in a standard WooCommerce environment. However, the impact is broad, as it facilitates privilege escalation or session token theft when an administrator views the compromised content. The vulnerability affects all versions of the Tabs Responsive plugin through 2.5."
}
CVE-2026-13718: Tabs Responsive Stored XSS (MEDIUM Severity, CVSS: 6.8) | Sceawere