PT-2026-73090 · WordPress · Wc Product Table Lite
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WC Product Table Lite versions prior to 5.6.1
Description
An unauthenticated CSS Injection issue exists via the
laptop scroll offset shortcode attribute. The wcpt ajax() AJAX handler, registered for wp ajax nopriv wcpt ajax, processes attacker-supplied attributes by JSON-decoding them and applying a filter that only removes specific characters ([ ] < >). The resulting value is passed through do shortcode() into the wcpt style sticky sidebar() function, where it is inserted directly into inline CSS without numeric casting or escaping. This allows unauthenticated attackers to inject arbitrary CSS declarations and rules on pages with a product table and sticky sidebar enabled. This can be used for UI redressing, phishing that bypasses Content Security Policies (CSPs) allowing inline styles, and data exfiltration using attribute-selectors combined with background-image URLs.Recommendations
Update to a version newer than 5.6.0.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wc Product Table Lite