CVE-2026-96816: WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trusted Shops Easy Integration for WooCommerceto a version that resolves this vulnerability.Fixed in 2.0.7
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation requires user interaction, as reflected by the UI:R attack vector.
Which installations are affected?
Trusted Shops Easy Integration for WooCommerce versions 2.0.6 and earlier are affected. The provided information does not state whether any particular plugin configuration is required.
What impact could successful exploitation have?
The severity vector indicates low potential impact to confidentiality, integrity, and availability, with scope changed. As an XSS issue, successful exploitation can cause attacker-supplied script to run in a victim's browser context.