What is CVE-2026-15441?
The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to and including 5.6.0 via the 'laptop_scroll_offset' shortcode attribute. This allows unauthenticated attackers to inject arbitrary CSS through the AJAX handler. The plugin should be immediately updated to the latest version.
Azərbaycanca: WordPress üçün WC Product Table Lite plaqini 5.6.0 və aşağı versiyalarında 'laptop_scroll_offset' shortcode atributu vasitəsilə CSS Injection zəifliyinə məruz qalır. Bu, autentifikasiya olunmamış istifadəçilərin AJAX handler üzərindən ixtiyari CSS kodu yeritməsinə imkan yaradır. Plaqin dərhal ən son versiyaya yenilənməlidir.
FAQ2
Which versions of the WC Product Table Lite plugin are affected by the CSS Injection vulnerability?
The vulnerability affects the WC Product Table Lite plugin versions up to and including 5.6.0.
How can an unauthenticated attacker exploit this vulnerability?
The attacker can inject arbitrary CSS through the AJAX handler via the 'laptop_scroll_offset' shortcode attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.