Cross Site Scripting Vulnerability in YITH WooCommerce Tab Manager by YITH
CVE-2026-97292

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-97292?

A Cross Site Scripting (XSS) vulnerability exists in the YITH WooCommerce Tab Manager plugin versions 2.15.0 and earlier. This flaw allows attackers to inject malicious scripts via crafted input, compromising the integrity of user sessions and allowing for a range of exploitation, including data theft and unauthorized access. It is crucial for users of this plugin to update to the latest version or apply necessary security patches to mitigate potential risks.

Affected Version(s)

YITH WooCommerce Tab Manager <= 2.15.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seongwon LEE | Patchstack Bug Bounty Program
.