Stored Cross-Site Scripting in eCommerce Product Catalog Plugin for WordPress
CVE-2026-76128

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 August 2026

What is CVE-2026-76128?

The eCommerce Product Catalog plugin for WordPress exhibits a vulnerability that allows for Stored Cross-Site Scripting due to inadequate input validation and output sanitization. Authenticated users with contributor-level access or higher can exploit this flaw by injecting malicious web scripts through the 'style' shortcode attribute. The risk arises from the fact that the malicious payload is stored within shortcode brackets, circumventing standard WordPress security measures such as wp_kses_post. When users access affected pages, these scripts are executed, potentially compromising user data and site security.

Affected Version(s)

eCommerce Product Catalog 0 <= 3.5.10

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.