Description
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch immediately
AI Analysis

Impact

The Tabs Responsive WordPress plugin version 2.5 and earlier fails to sanitize the content of WooCommerce product tab fields before storing and rendering them. A shop manager can save arbitrary JavaScript in a product tab, which then executes in the browsers of every visitor who views that product page, including administrators. This stored cross‑site scripting can be leveraged to hijack sessions, steal cookies, deface content, or perform malicious redirects. The flaw is a classic stored XSS weakness where uncontrolled input is persisted and later reflected to users. The worst‑case scenario involves full compromise of the website if an attacker controls a shop manager account.

Affected Systems

Any WordPress site that implements the Tabs Responsive plugin up to version 2.5, coupled with a WooCommerce installation where shop manager roles are granted permission to edit product tab content. The vendor of the plugin is listed only as "Tabs Responsive" and the official plugin author is not disclosed, making it difficult to track the exact development lineage.

Risk and Exploitability

The vulnerability presents a high‑risk stored XSS surface. An attacker must possess shop manager privileges to inject the malicious payload, but once injected the code runs for every visitor who views the product page, including administrators. With no EPSS score reported and the issue not listed in the CISA KEV catalog, the exploitation probability is unknown, yet the lack of input sanitization combined with the broad user exposure indicates a serious threat to all site users. The attacker can hijack sessions, steal cookies, deface content, or perform malicious redirects.

Generated by OpenCVE AI on October 2, 2026 at 07:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Tabs Responsive to a version newer than 2.5 or remove the plugin if no update is available
  • If an update is unavailable, revoke shop manager capability to add or edit product tab content and restrict editing to safe editors only
  • Apply a site‑wide output sanitizer that escapes or strips <script> tags from WooCommerce product tab content
  • As a temporary measure, disable product tabs on the storefront to prevent the vulnerable code from rendering

Generated by OpenCVE AI on October 2, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
Title Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T06:00:24.997Z

Reserved: 2026-06-29T14:06:03.048Z

Link: CVE-2026-13718

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T06:16:40.123

Modified: 2026-10-02T06:16:40.123

Link: CVE-2026-13718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')