CVE-2026-96814: WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
Affected Software
1 affected component
WordPress WooCommerce Product Table Lite<=5.6.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce Product Table Liteto a version that resolves this vulnerability.Fixed in 5.6.9
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an attacker to have a WordPress account or other privileges?
No. The vulnerability is rated with no privileges required and network attack access, so an unauthenticated attacker can attempt exploitation remotely.
2
Is user interaction required for exploitation?
Yes. The CVSS vector indicates user interaction is required, meaning a user must interact with attacker-controlled content or a crafted request for the attack to succeed.
3
What is the assessed impact if exploitation succeeds?
The supplied CVSS vector rates confidentiality, integrity, and availability impact as low, with scope changed. The overall severity is high with a score of 7.1.