What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Tab Manager yith-woocommerce-tab-manager.This issue affects YITH WooCommerce Tab Manager: from n/a through <= 1.35.0.
Explanation of Vulnerability in Simple Terms
02Summary
YITH WooCommerce Tab Manager versions up to 1.35.0 contain a stored cross-site scripting (XSS) vulnerability. An authenticated admin can inject malicious scripts into tab content that execute in the browsers of other users viewing the site. The vulnerability requires admin privileges and user interaction to exploit, but can affect site visitors and other administrators.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in visitors' browsers when they view affected tabs.
Potential impact on your site
04Site Impact
A compromised admin account can inject malware or steal visitor data through tab content.
Conditions required to exploit
05Prerequisites
Admin-level access to the site and a user must view the page containing the injected tab.
Key dates
06Disclosure timeline
June 8, 2024
CVE published
April 28, 2026
Record updated