high · CVSS v3 7.5
CVE-2026-13718
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storin…
Description
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —