rootpwn

high · CVSS v3 7.5

CVE-2026-13718

The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storin…

Description

The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.5
CVSS v4
—
EPSS
—

← All CVEs