Junglewise Threat Intelligence

CVE-2026-85575: ShopEngine Elementor WooCommerce Builder Addon stored XSS in product title header

CVE-2026-85575 · Severity: medium · CVSS 6.4 · Published 2026-09-15

Executive brief

ShopEngine is a WordPress plugin that allows website administrators to build WooCommerce product pages using the Elementor visual editor. The plugin contains a stored cross-site scripting (XSS) vulnerability that allows authenticated authors and editors to inject malicious JavaScript into pages. When other users (including administrators or customers) visit affected pages, the injected script executes in their browsers, potentially leading to account takeover, session hijacking, or data theft.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the 'shopengine_product_title_header_size' parameter affecting ShopEngine versions up to 4.9.5. The plugin fails to properly sanitize and escape user input when processing this parameter, allowing authenticated users with Author-level privileges or higher to inject arbitrary HTML and JavaScript into pages. The injected payload is stored in the database and executes in the browser of any user who subsequently views the affected page. This attack requires authentication but poses a significant risk in multi-author WordPress environments where trust between users is not absolute. A patch is available in versions following 4.9.5.

Affected products

  • ShopEngine Elementor WooCommerce Builder Addon up to and including 4.9.5

Timeline

  • 2026-09-15: disclosed

References