Vulnerabilities and security researches fortabs-responsive tabs-responsive
Direction: descendingOct 04, 2026
Tabs Responsive – With WooCommerce Product Tabs Extension # CVE-2026-13718
- CVE, Research URL
- Date
- Oct 02, 2026
- Research Description
- The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
- Affected versions
-
max 2.5.
- Status
-
vulnerable
Jul 29, 2026
Tabs Responsive – With WooCommerce Product Tabs Extension # CVE-2026-65550
- CVE, Research URL
- Date
- Jul 23, 2026
- Research Description
- Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
- Affected versions
-
max 2.5.
- Status
-
vulnerable
Jun 06, 2024
Tabs Responsive – With WooCommerce Product Tabs Extension # CVE-2018-5312
- CVE, Research URL
- Date
- Jan 09, 2018
- Research Description
- The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
- Affected versions
-
max 2.0.0.
- Status
-
vulnerable
Tabs Responsive – With WooCommerce Product Tabs Extension # CVE-2022-1298
- CVE, Research URL
- Date
- May 23, 2022
- Research Description
- The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged users with a role as low as editor to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected versions
-
max 2.2.8.
- Status
-
vulnerable