CVE-2026-105056: WordPress eCommerce Product Catalog plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress eCommerce Product Catalogto a version that resolves this vulnerability.Fixed in 3.6.3
Event History
Frequently Asked Questions
What access and conditions are required for exploitation?
The CVSS vector indicates that exploitation is network-accessible, has low attack complexity, requires low privileges, and requires user interaction. An attacker would need an account or capability associated with low-level privileges before attempting exploitation.
Which installations should be treated as affected?
Installations running impleCode eCommerce Product Catalog version 3.6.2 or earlier should be treated as potentially affected. The affected-version range begins at an unspecified version, so the available data does not identify an unaffected earlier release.
What is the potential impact if exploitation succeeds?
The issue is stored XSS, meaning malicious content can persist and execute when viewed by another user. The provided CVSS assessment indicates low confidentiality, integrity, and availability impact, with scope changed.