CVE-2026-3574Disclosure

LOWCVSS 4.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versions up to and including 1.0.4. This is due to insufficient input sanitization (no sanitize callback in register_setting()) and missing output escaping (no esc_attr() in the field_callback() printf output) on user-supplied values. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in the plugin settings page that will execute whenever a user accesses the settings page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Technical Details · 2026-04-09: 204-0904-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3574 📊 Severity: 4.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3574 #CVE-2026-3574 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/0GOSiyJtBZ

    Post summary

    The tweet informs readers about CVE-2026-3574 affecting WordPress with a medium risk level, but it provides no technical details, exploitation evidence, or remediation guidance.

    0000034
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3574 The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Siz… https://www.cve.org/CVERecord?id=CVE-2026-3574 ----- Traducción: CVE-2026-3574 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑3574, a stored XSS flaw in the Experto Dashboard for WooCommerce WordPress plugin, providing only a brief description and a link to the CVE record.

    0000027
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3574 The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Siz… https://www.cve.org/CVERecord?id=CVE-2026-3574

    Post summary

    The text announces that CVE‑2026‑3574 impacts the Experto Dashboard WooCommerce plugin with a stored XSS flaw in its settings fields, but does not provide a PoC, exploit, or patch details.

    00000191
    57.0K followersView on X

Explore more