The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenti…
Medium CVSS 5.3
Summary
The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenticated wcpt_ajax() AJAX handler. The handler is registered for wp_ajax_nopriv_wcpt_ajax, JSON-decodes attacker-supplied attributes, only allowlists key names (not values), applies a preg_replace that strips only [ ] < >, and passes the value through do_shortcode into wcpt_style__sticky_sidebar(), whe…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/main.php#L2677
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/main.php#L2686
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.1.0/style-functions.php#L995
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/main.php#L2677
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/main.php#L2686
- https://plugins.trac.wordpress.org/browser/wc-product-table-lite/tags/5.4.0/style-functions.php#L995
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3638932%40wc-product-table-lite&new=3638932%40wc-product-table-lite
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6c0a8be1-8853-4863-90e5-af3831f800e9?source=cve
Timeline
- nvd_ingest NVD