CVE-2026-10104PoC

MEDIUMCVSS 4.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-06: 1Mentions · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-08: 1Exploit Tool / Code · 2026-07-06: 1Exploit Tool / Code · 2026-07-08: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-08: 107-0607-08
Signal classification1 categories
PoC
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    🚨 CVE-2026-10104 PoC published GitHub: https://github.com/Ravi-lk/CVE-2026-10104-POC A PoC is available for an authenticated stored XSS issue in Product Video Gallery for WooCommerce. The flaw affects older versions of the WordPress plugin and can allow JavaScript execution on public product pages after a user with product-editing access injects the payload. Fixed in 1.5.1.9.

    Post summary

    A proof‑of‑concept for CVE-2026-10104, an authenticated stored XSS in the WooCommerce "Product Video Gallery" plugin, is now hosted on GitHub; the flaw is fixed in version 1.5.1.9 and no active exploitation is reported.

    1160913215.9K
    233.2K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CVE-2026-10104: A PoC has been released for a stored XSS vulnerability in the Product Video Gallery for WooCommerce plugin. The issue is fixed in v1.5.1.9. 🔗 https://github.com/Ravi-lk/CVE-2026-10104-POC #CyberSecurity #CVE #WordPress #WooCommerce #ThreatWire

    Post summary

    A proof‑of‑concept demonstrating a stored XSS issue in the WooCommerce Product Video Gallery plugin is available on GitHub, and the vulnerability has been fixed in version 1.5.1.9.

    0001091
    65 followersView on X

Explore more