Sceawere
Vulnerability Detail
CVE-2026-96816UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Trusted Shops
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- vendidero
- Product
- Trusted Shops Easy Integration for WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:30.910Z",
"pubdate": "2026-09-30T13:17:30.910Z",
"executiveSummary": "The Trusted Shops Easy Integration for WooCommerce plugin, specifically versions 2.0.6 and below, contains a critical vulnerability categorized as Unauthenticated Cross-Site Scripting (XSS).\nThis vulnerability stems from improper neutralization of user-supplied input before rendering it in the browser, allowing an attacker to inject and execute arbitrary JavaScript code within the context of a victim's session.\nThe impact of this flaw is significant, as it does not require authentication or elevated privileges to exploit, meaning any remote attacker can initiate the attack.\nSuccessful exploitation allows the attacker to perform actions on behalf of the victim, potentially leading to unauthorized data access, session hijacking, or the defacement of the affected WooCommerce store.\nThis vulnerability poses a substantial risk to site integrity and user data confidentiality, necessitating immediate action to mitigate the risk through remediation or vendor-provided updates.",
"technicalDetails": "The vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw present in the Trusted Shops Easy Integration for WooCommerce plugin, affecting all versions up to and including 2.0.6.\nThe root cause of this vulnerability lies in the plugin's failure to properly sanitize and validate input parameters before reflecting them into the HTML response delivered to the user's browser.\nIn a typical attack scenario, the plugin takes input from a URL parameter or a POST request without adequate output encoding. An attacker can craft a malicious URL containing a payload—typically a script tag—and induce an authenticated or unauthenticated user to click it.\nWhen the victim accesses the crafted link, the plugin echoes the unsanitized input directly into the generated HTML. Because the browser interprets this input as executable code, the malicious JavaScript executes within the security context of the vulnerable WordPress site.\nThe attack flow proceeds as follows: First, the attacker identifies an input vector within the plugin that is reflected in the frontend. Second, the attacker crafts a malicious payload, such as '<script>alert(document.cookie)</script>', and embeds it into that input parameter. Third, the attacker distributes this link to unsuspecting users, potentially leveraging social engineering. When the victim interacts with the link, the server processes the request and embeds the payload into the response page. Finally, the victim's browser executes the script, granting the attacker the ability to steal session cookies, capture sensitive data, or perform unauthorized administrative actions if the victim happens to be an administrator.\nThis vulnerability is particularly severe due to its accessibility. It does not require the attacker to have an account, specific privileges, or pre-existing access to the administrative dashboard, effectively increasing the attack surface to any visitor of the affected WooCommerce store.\nPost-exploitation impact includes, but is not limited to, unauthorized session hijacking, arbitrary content modification, and the potential redirection of site visitors to malicious external sites, all of which compromise the security posture and reputation of the platform."
}