PT-2026-31568 · Unknown+1 · Woocommerce+1

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-3574

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Experto Dashboard for WooCommerce plugin for WordPress versions up to and including 1.0.4
Description The Experto Dashboard for WooCommerce plugin for WordPress is susceptible to Stored Cross-Site Scripting through its settings fields, including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight'. The root cause is insufficient input sanitization, specifically the absence of a sanitize callback in register setting(), and a lack of output escaping, with missing esc attr() in the field callback() printf output. This allows authenticated attackers with Administrator-level access or higher to inject arbitrary web scripts into the plugin settings page, which will execute when any user accesses the settings page. This issue is limited to multi-site installations and those where unfiltered html has been disabled.
Recommendations Update to a version beyond 1.0.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3574

Affected Products

Experto Dashboard For Woocommerce
Woocommerce