
🚨 CVE-2026-10104 PoC published GitHub: https://github.com/Ravi-lk/CVE-2026-10104-POC A PoC is available for an authenticated stored XSS issue in Product Video Gallery for WooCommerce. The flaw affects older versions of the WordPress plugin and can allow JavaScript execution on public product pages after a user with product-editing access injects the payload. Fixed in 1.5.1.9.
Post summary
A proof‑of‑concept for CVE-2026-10104, an authenticated stored XSS in the WooCommerce "Product Video Gallery" plugin, is now hosted on GitHub; the flaw is fixed in version 1.5.1.9 and no active exploitation is reported.

