Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Reflected XSS.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 3.4.1.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The flaw is an improper neutralization of input during web page generation that allows reflected cross‑site scripting. An attacker can supply specially crafted data that is echoed back into the page, enabling the execution of arbitrary JavaScript in the victim’s browser. This can lead to session hijacking, credential theft, or other attacks performed in the context of the authenticated user. The weakness is a classic unsanitized input error, listed as CWE‑79.

Affected Systems

The vulnerability exists in Mamunur Rashid’s WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin, versions up through 3.4.1. Users running any of these versions are potentially exposed.

Risk and Exploitability

The vulnerability receives a CVSS score of 7.1, indicating a moderate‑to‑high severity. No EPSS score is available, and it is not yet listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not been observed. The likely attack vector is via reflected input in plugin interfaces, requiring the attacker to trick a user into visiting a crafted URL or submitting a form containing malicious payloads.

Generated by OpenCVE AI on October 9, 2026 at 12:08 UTC.

Remediation

Vendor Solution

Update the WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin to the latest available version (at least 3.4.2).


OpenCVE Recommended Actions

  • Update the WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin to version 3.4.2 or later.
  • If an immediate update is not feasible, disable or delete the plugin until the fix is applied to prevent exposure through the plugin’s input fields.
  • Deploy a web application firewall or site‑wide security plugin to block reflected cross‑site scripting attempts and sanitize user input in addition to the plugin update.

Generated by OpenCVE AI on October 9, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Reflected XSS.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 3.4.1.
Title WordPress ShopBuilder – Elementor WooCommerce Builder Addons plugin <= 3.4.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:19.652Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95596

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:42.370

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-95596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')