CVE-2026-97292: WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Affected Software
1 affected component
YITH WooCommerce Tab Manager<=2.15.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YITH WooCommerce Tab Managerto a version that resolves this vulnerability.Fixed in 2.15.1
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
YITH WooCommerce Tab Manager versions 2.15.0 and earlier are identified as affected.
2
What access does an attacker need to exploit this issue?
The vector indicates network access, low attack complexity, and low privileges required. Exploitation also requires user interaction.
3
What is the potential impact?
The reported impact includes low-level effects on confidentiality, integrity, and availability, with scope changed. The weakness is cross-site scripting.