Executive brief
The eCommerce Product Catalog is a WordPress plugin that allows site administrators to display product listings on their pages. Authenticated users with contributor-level access or higher can inject malicious scripts into pages through the plugin's shortcode feature, which will execute whenever anyone views those pages. This could allow attackers to steal customer data, redirect users to phishing sites, or compromise website functionality.
Technical details
The plugin contains a stored cross-site scripting (XSS) vulnerability in the 'style' attribute of its shortcode handler. The vulnerability exists because the plugin fails to properly sanitize and escape user-supplied input in shortcode attributes. The attack vector requires authentication (contributor-level access or above), and the malicious payload bypasses WordPress's save-time wp_kses_post sanitization by being stored within shortcode brackets without HTML tags. The tainted output is only generated at render time by the shortcode handler, allowing arbitrary JavaScript execution in the context of any user viewing the affected page. Patches are available in versions after 3.5.10.
Affected products
- WordPress.org eCommerce Product Catalog up to and including 3.5.10
Timeline
- 2026-08-25: disclosed
- other: CVE-2026-76128 assigned