WPIntell

Source evidence

Cross-Site Scripting security vulnerability

Tabs Responsive – With WooCommerce Product Tabs Extension · support · 2024-11-04T22:47:00+00:00

questionsentiment
highseverity
0.95relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 35 rows with source links

17.1% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
drdavidwelham resolved
IMPORTANT: Tabs – Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. https://patchstack.com/database/vulnerability/vc-tabs/wordpress-tabs-plugin-4-0-6-cross-site-scripting-xss-vulnerability Please fix this ASAP and alert users once repaired. Hello, Is shared URL details belong to our plugin…may be its belong to vc-tabs. Are you getting any issues in our plugin? Please explain your issue properly by sharing short video or via screenshot. Thanks Yes, so sorry, you are 100% correct, this security alert belongs to VC-Tabs, (a developer named “Biplob Adhikari.”)… I have his TABS accordions plugin installed on my website. Also, noticed that his plugin was removed from WordPress back in March 2024 for security issues. https://wordpress.org/plugins/vc-tabs/

Comments

2 shown
deepesh paliwal 2024-11-05T17:38:00+00:00

Hello, Is shared URL details belong to our plugin…may be its belong to vc-tabs. Are you getting any issues in our plugin? Please explain your issue properly by sharing short video or via screenshot. Thanks

drdavidwelham 2024-11-05T23:10:00+00:00

Yes, so sorry, you are 100% correct, this security alert belongs to VC-Tabs, (a developer named “Biplob Adhikari.”)… I have his TABS accordions plugin installed on my website. Also, noticed that his plugin was removed from WordPress back in March 2024 for security issues. https://wordpress.org/plugins/vc-tabs/