Junglewise Threat Intelligence

CVE-2026-65550: wpshopmart Tabs Cross-Site Scripting in WordPress plugin

CVE-2026-65550 · Severity: medium · CVSS 5.9 · Published 2026-07-23

Executive brief

The Tabs plugin for WordPress, which is used to create responsive tabbed content on websites, contains a security vulnerability that allows users with 'Shop Manager' privileges to inject malicious scripts. If an attacker successfully exploits this, they could redirect visitors to malicious websites, display unauthorized advertisements, or steal session information when a site administrator views the affected content. This could lead to unauthorized site changes or a loss of visitor trust.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the wpshopmart Tabs (tabs-responsive) plugin for WordPress in versions up to 2.5. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Shop Manager' or higher privileges can inject malicious JavaScript into the plugin's tab components. The exploit requires a victim (typically an administrator) to interact with the affected page or administrative interface. Successful exploitation allows for the execution of arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.

Affected products

  • wpshopmart Tabs (tabs-responsive) <= 2.5

Timeline

  • 2026-06-24: disclosed: Vulnerability reported by researcher Ananda Dhakal via Patchstack.
  • 2026-07-22: advisory: Initial advisory published by Patchstack.
  • 2026-07-23: other: CVE record published in NVD.

References