Stored Cross-Site Scripting in eCommerce Product Catalog Plugin for WordPress
CVE-2026-76128
6.4MEDIUM
What is CVE-2026-76128?
The eCommerce Product Catalog plugin for WordPress exhibits a vulnerability that allows for Stored Cross-Site Scripting due to inadequate input validation and output sanitization. Authenticated users with contributor-level access or higher can exploit this flaw by injecting malicious web scripts through the 'style' shortcode attribute. The risk arises from the fact that the malicious payload is stored within shortcode brackets, circumventing standard WordPress security measures such as wp_kses_post. When users access affected pages, these scripts are executed, potentially compromising user data and site security.
Affected Version(s)
eCommerce Product Catalog 0 <= 3.5.10