Cross-Site Scripting Vulnerability in HashThemes Mini Ajax Cart for WooCommerce
CVE-2026-6370

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-6370?

The HashThemes Mini Ajax Cart for WooCommerce contains a vulnerability that allows for improper neutralization of user input when generating web pages. This results in Stored Cross-Site Scripting (XSS) attacks, which can be exploited by attackers to inject malicious scripts into web pages viewed by other users. As a result, sensitive data can be compromised, leading to potential security breaches. Affected versions range from n/a through 1.3.4, making it essential for website administrators to update their plugins to ensure protection against this risk.

Affected Version(s)

Mini Ajax Cart for WooCommerce <= 1.3.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Osman ERBAS (0110m4n) | Patchstack Bug Bounty Program
.