
CVE-2026-76128 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, … https://www.cve.org/CVERecord?id=CVE-2026-76128
Post summary
An XSS vulnerability is disclosed in the WordPress eCommerce Product Catalog plugin, caused by a malicious 'style' shortcode attribute.

