Skip to content
Threat Feed
high advisory

Stored XSS in WP-Lister Lite for eBay WordPress Plugin

The WP-Lister Lite for eBay plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in its AJAX Cron Handler allowing unauthenticated script injection.

CVE search metadata

CVE search record: CVE-2026-18595. Severity: high. CVSS: 7.2. KEV: no. Product: WP-Lister Lite for eBay (<= 3.8.9). Brief: Stored XSS in WP-Lister Lite for eBay WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-wp-lister-xss/

The WP-Lister Lite for eBay plugin for WordPress, in versions up to and including 3.8.9, is affected by a Stored Cross-Site Scripting (XSS) vulnerability. The flaw resides in the AJAX Cron Handler, which fails to perform adequate input sanitization and output escaping on request parameters. This vulnerability allows an unauthenticated attacker to inject malicious JavaScript into the plugin settings or associated pages. When an administrative user or other authenticated user views the compromised page, the attacker-supplied script executes within the context of the victim's browser session. This can lead to unauthorized actions, session hijacking, or the defacement of the affected WordPress site. Defenders should monitor web logs for anomalous POST requests directed at the plugin's AJAX endpoints and ensure all plugins are updated to the latest version.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of users accessing the affected site. This could result in unauthorized administrative actions, the theft of session cookies, or further compromise of the WordPress environment. The vulnerability impacts all users of WP-Lister Lite for eBay running versions 3.8.9 or earlier.

Recommendation

Update the WP-Lister Lite for eBay plugin to the latest version immediately to remediate CVE-2026-18595. In environments where patching is delayed, monitor server access logs for suspicious input patterns within requests targeting plugin AJAX endpoints.


Immediate actions

Upgrade WP-Lister Lite for eBay to the latest version.

IT Operations 24h

Mitigations

Upgrade to the version succeeding 3.8.9

immediate IT Operations

CVE-2026-18595