Description
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
Published: 2026-07-23
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unescaped cross‑site scripting flaw present in all releases of the WordPress Tabs plugin up to and including version 2.5. It allows an attacker to inject arbitrary JavaScript into content that is rendered to visitors of the site, potentially impacting data confidentiality and integrity of the website. No other consequences are specified in the official description.

Affected Systems

WordPress sites that have installed the Tabs plugin from wpshopmart (Tabs) with a version equal to or older than 2.5 are affected. The flaw applies to any installation where the plugin is active and renders user‑supplied content without sanitization.

Risk and Exploitability

The CVSS score of 5.9 classifies the flaw as moderate severity. The EPSS score is less than 1% indicating a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s user interface or configuration pages, where a malicious actor can input crafted content that will be displayed unescaped to site visitors, as inferred from the nature of a reflected XSS flaw.

Generated by OpenCVE AI on August 4, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available update for the Tabs plugin that addresses the XSS flaw, as the vendor has not published a specific version fix.
  • If the plugin is not required for site functionality, uninstall or deactivate it entirely to eliminate the attack surface.
  • Configure a Content Security Policy that disallows inline script execution to mitigate the impact if an attacker manages to insert malicious code.

Generated by OpenCVE AI on August 4, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpshopmart
Wpshopmart tabs
Vendors & Products Wordpress
Wordpress wordpress
Wpshopmart
Wpshopmart tabs

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
Title WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpshopmart Tabs
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:35:46.597Z

Reserved: 2026-07-22T08:54:17.066Z

Link: CVE-2026-65550

cve-icon Vulnrichment

Updated: 2026-07-23T13:35:42.695Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:47.230

Modified: 2026-07-23T14:18:01.160

Link: CVE-2026-65550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')