SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-57396

HIGH · CVSS 7.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The Flintop Free Gifts for WooCommerce plugin is vulnerable to stored cross-site scripting (XSS) due to improper input neutralization during web page generation, affecting versions up to 13.1.0. This vulnerability can allow attackers to inject malicious scripts that execute in the context of users' browsers, potentially compromising user data and site integrity. E-commerce site administrators using this plugin should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-57396
Severity
HIGH
CVSS
7.1
EPSS
0.18%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0.