Sceawere

Vulnerability Detail

CVE-2026-96814UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in WooCommerce Product Table Lite

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
WP Titan Labs
Product
WooCommerce Product Table Lite
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-09-30T13:17:30.623Z",
  "pubdate": "2026-09-30T13:17:30.623Z",
  "executiveSummary": "The WooCommerce Product Table Lite plugin, in versions up to and including 5.6.7, is susceptible to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw arises from the improper sanitization of user-supplied input before reflecting it within the administrative or front-end interface of the WordPress environment.\nThe vulnerability allows remote, unauthenticated attackers to inject malicious JavaScript into the victim's browser session. By enticing an administrator or a user with elevated privileges to interact with a crafted URL, an attacker can execute arbitrary scripts within the context of the affected site.\nSuccessful exploitation poses significant risks, including the potential for unauthorized administrative actions, session hijacking, credential theft, and the redirection of users to malicious external domains. Given the plugin's function within WooCommerce, this vulnerability impacts site integrity and potentially compromises sensitive customer or administrative data.\nAs the attack requires no prior authentication, it is classified as a high-risk vector. Remediation necessitates an immediate upgrade to a patched version once available or the implementation of strict input filtering and output encoding protocols to neutralize the injection path.",
  "technicalDetails": "The vulnerability is identified as a classic Reflected Cross-Site Scripting (XSS) flaw located within the query parameter handling logic of the WooCommerce Product Table Lite plugin. The root cause is the failure to implement sufficient output encoding or input validation on specific parameters passed through GET requests that are subsequently processed and rendered back to the user's browser by the plugin.\nDuring the standard execution flow, the plugin receives parameters to define the layout or filtering criteria of the product table. In affected versions, the input provided to these parameters is not validated against a whitelist of expected characters, nor is it properly escaped for the HTML context in which it is displayed. Consequently, an attacker can supply a specially crafted string containing script tags (e.g., <script>alert(document.cookie)</script>) or event handlers (e.g., onload, onerror) within the URL.\nWhen an unsuspecting user, particularly one with active session cookies (such as an administrator), accesses a link containing this malicious payload, the application reflects the script directly into the HTML response. The browser, trusting the server's output, executes the injected JavaScript within the security origin of the vulnerable WordPress site.\nThe attack vector is characterized by the following steps: 1) The attacker constructs a malicious URL incorporating a JavaScript payload in the susceptible query parameter. 2) The attacker lures a victim to click the link or triggers the request via an automated vector. 3) The WooCommerce Product Table Lite plugin processes the input and embeds it into the web page without neutralization. 4) The victim's browser executes the payload, granting the attacker access to the DOM, session tokens, and administrative functionality.\nThis vulnerability is reachable over the network without any authentication or privilege requirements. The post-exploitation impact is severe, as the attacker can perform actions on behalf of the victim, such as modifying plugin settings, creating new administrative accounts, or injecting malicious content into product pages. The lack of Content Security Policy (CSP) headers or robust sanitization libraries within the vulnerable code path further facilitates the exploitation process."
}
CVE-2026-96814: Unauthenticated XSS in WooCommerce Product Table Lite (HIGH Severity, CVSS: 7.1) | Sceawere