CVE-2026-13718: Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content

Published Oct 2, 2026
·
Updated

The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.

Affected Software

1 affected component
Tabs Responsive<=2.5

Event History

Oct 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is exposed to the payload?

An attacker needs Shop Manager-level or higher access to add malicious WooCommerce product-tab content. The stored JavaScript executes when a user views the affected product page, including when that user is an administrator.

2

What access and interaction are required for exploitation?

The attacker must already have Shop Manager+ privileges and must be able to save content in WooCommerce product tabs. A victim must then visit the affected product page for the stored script to execute.

3

Are sites using the affected plugin version range exposed by default?

Exposure depends on use of WooCommerce product tabs and whether a Shop Manager+ account can create or modify tab content. The provided data does not establish that every default installation is exploitable without those conditions.

4

How can I check whether my site may be affected?

Check whether Tabs Responsive is installed at version 2.5 or earlier, then review WooCommerce product-tab content created or modified by Shop Manager+ accounts for embedded JavaScript or other unexpected markup.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203