Junglewise Threat Intelligence

CVE-2026-57360: impleCode eCommerce Product Catalog unauthenticated XSS

CVE-2026-57360 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The eCommerce Product Catalog plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially hijack user sessions, redirect customers to fraudulent websites, or deface the online store. This could lead to a loss of customer trust and unauthorized access to sensitive management areas of the site.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the impleCode eCommerce Product Catalog plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to steal session cookies or perform actions on behalf of an authenticated administrator. The vulnerability is resolved in version 3.5.5.

Affected products

  • impleCode eCommerce Product Catalog <= 3.5.4

Timeline

  • 2026-05-15: other: Reported by Jakub Herman
  • 2026-07-01: disclosed: Initial disclosure by Patchstack
  • 2026-07-02: advisory: NVD publication date

References

Related threats