Impact
The Tabs Responsive WordPress plugin version 2.5 and earlier fails to sanitize the content of WooCommerce product tab fields before storing and rendering them. A shop manager can save arbitrary JavaScript in a product tab, which then executes in the browsers of every visitor who views that product page, including administrators. This stored cross‑site scripting can be leveraged to hijack sessions, steal cookies, deface content, or perform malicious redirects. The flaw is a classic stored XSS weakness where uncontrolled input is persisted and later reflected to users. The worst‑case scenario involves full compromise of the website if an attacker controls a shop manager account.
Affected Systems
Any WordPress site that implements the Tabs Responsive plugin up to version 2.5, coupled with a WooCommerce installation where shop manager roles are granted permission to edit product tab content. The vendor of the plugin is listed only as "Tabs Responsive" and the official plugin author is not disclosed, making it difficult to track the exact development lineage.
Risk and Exploitability
The vulnerability presents a high‑risk stored XSS surface. An attacker must possess shop manager privileges to inject the malicious payload, but once injected the code runs for every visitor who views the product page, including administrators. With no EPSS score reported and the issue not listed in the CISA KEV catalog, the exploitation probability is unknown, yet the lack of input sanitization combined with the broad user exposure indicates a serious threat to all site users. The attacker can hijack sessions, steal cookies, deface content, or perform malicious redirects.
OpenCVE Enrichment