CVE-2026-13718: CWE-79 Cross-Site Scripting (XSS) in Tabs Responsive
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
AI Analysis
Technical Summary
CVE-2026-13718 is a cross-site scripting (CWE-79) vulnerability in the Tabs Responsive WordPress plugin versions up to 2.5. The vulnerability occurs due to lack of sanitization of WooCommerce product tab content, allowing a shop manager to store malicious JavaScript. This script executes in the context of any user viewing the product page, potentially leading to session hijacking, privilege escalation, or other XSS-related impacts.
Potential Impact
An authenticated shop manager can inject arbitrary JavaScript into WooCommerce product tabs, which executes when any user, including administrators, views the product page. This can lead to unauthorized actions performed in the context of the victim's session, data theft, or other malicious activities typical of stored XSS vulnerabilities.
Mitigation Recommendations
No patch or official fix is currently documented. Users should monitor the vendor's advisory for updates. Until a fix is available, restrict shop manager privileges to trusted users only and consider disabling or limiting the use of the Tabs Responsive plugin for WooCommerce product tabs to reduce exposure.
CVE-2026-13718: CWE-79 Cross-Site Scripting (XSS) in Tabs Responsive
Description
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
CVSS v3.1
Score 6.8medium
Affected software
Tabs Responsive
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-13718 is a cross-site scripting (CWE-79) vulnerability in the Tabs Responsive WordPress plugin versions up to 2.5. The vulnerability occurs due to lack of sanitization of WooCommerce product tab content, allowing a shop manager to store malicious JavaScript. This script executes in the context of any user viewing the product page, potentially leading to session hijacking, privilege escalation, or other XSS-related impacts.
Potential Impact
An authenticated shop manager can inject arbitrary JavaScript into WooCommerce product tabs, which executes when any user, including administrators, views the product page. This can lead to unauthorized actions performed in the context of the victim's session, data theft, or other malicious activities typical of stored XSS vulnerabilities.
Mitigation Recommendations
No patch or official fix is currently documented. Users should monitor the vendor's advisory for updates. Until a fix is available, restrict shop manager privileges to trusted users only and consider disabling or limiting the use of the Tabs Responsive plugin for WooCommerce product tabs to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-29T14:06:03.048Z
- State
- PUBLISHED
Threat ID: 6abf4919a43b0b3b897a0eb7
Added to database: 10/02/2026, 06:03:05 UTC
Last enriched: 10/02/2026, 06:16:46 UTC
Last updated: 10/03/2026, 03:09:37 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.