PT-2026-73090 · WordPress · Wc Product Table Lite

·

CVE-2026-15441

·

Published

2026-08-16

·

Updated

2026-08-18

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WC Product Table Lite versions prior to 5.6.1
Description An unauthenticated CSS Injection issue exists via the laptop scroll offset shortcode attribute. The wcpt ajax() AJAX handler, registered for wp ajax nopriv wcpt ajax, processes attacker-supplied attributes by JSON-decoding them and applying a filter that only removes specific characters ([ ] < >). The resulting value is passed through do shortcode() into the wcpt style sticky sidebar() function, where it is inserted directly into inline CSS without numeric casting or escaping. This allows unauthenticated attackers to inject arbitrary CSS declarations and rules on pages with a product table and sticky sidebar enabled. This can be used for UI redressing, phishing that bypasses Content Security Policies (CSPs) allowing inline styles, and data exfiltration using attribute-selectors combined with background-image URLs.
Recommendations Update to a version newer than 5.6.0.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15441

Affected Products

Wc Product Table Lite