What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.0.
Explanation of Vulnerability in Simple Terms
02Summary
A stored cross-site scripting (XSS) vulnerability in Additional Custom Product Tabs for WooCommerce versions up to 1.7.0 allows authenticated users to inject malicious scripts into product tabs. When other users view the affected product page, the injected code executes in their browser. This can lead to session hijacking, credential theft, or malware distribution.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs when other users view a product page.
Potential impact on your site
04Site Impact
Customers' sessions and credentials can be compromised; site reputation and trust are at risk.
Conditions required to exploit
05Prerequisites
Attacker must be logged in with at least low-level privileges and the victim must visit the affected product page.
Key dates
06Disclosure timeline
April 15, 2025
CVE published
April 28, 2026
Record updated