CVE-2026-13718: Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is exposed to the payload?
An attacker needs Shop Manager-level or higher access to add malicious WooCommerce product-tab content. The stored JavaScript executes when a user views the affected product page, including when that user is an administrator.
What access and interaction are required for exploitation?
The attacker must already have Shop Manager+ privileges and must be able to save content in WooCommerce product tabs. A victim must then visit the affected product page for the stored script to execute.
Are sites using the affected plugin version range exposed by default?
Exposure depends on use of WooCommerce product tabs and whether a Shop Manager+ account can create or modify tab content. The provided data does not establish that every default installation is exploitable without those conditions.
How can I check whether my site may be affected?
Check whether Tabs Responsive is installed at version 2.5 or earlier, then review WooCommerce product-tab content created or modified by Shop Manager+ accounts for embedded JavaScript or other unexpected markup.