A vulnerability, which was classified as problematic, has been found in WC Product Table Lite Plugin up to 5.6.0 on WordPress. Impacted is the function wcpt_style__sticky_sidebar of the component Shortcode Handler. Performing a manipulation of the argument laptop_scroll_offset results in cross site scripting.

This vulnerability is reported as CVE-2026-15441. The attack is possible to be carried out remotely. No exploit exists.