Cross-Site Scripting Vulnerability in HashThemes Mini Ajax Cart for WooCommerce
CVE-2026-6370
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2026
What is CVE-2026-6370?
The HashThemes Mini Ajax Cart for WooCommerce contains a vulnerability that allows for improper neutralization of user input when generating web pages. This results in Stored Cross-Site Scripting (XSS) attacks, which can be exploited by attackers to inject malicious scripts into web pages viewed by other users. As a result, sensitive data can be compromised, leading to potential security breaches. Affected versions range from n/a through 1.3.4, making it essential for website administrators to update their plugins to ensure protection against this risk.
Affected Version(s)
Mini Ajax Cart for WooCommerce <= 1.3.4
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ali Osman ERBAS (0110m4n) | Patchstack Bug Bounty Program