WordPress 的 WooCommerce 插件 WPC Smart Quick View 存在反射型跨站脚本漏洞(Reflected Cross-Site Scripting)。在 4.4.0 及更早版本中,该漏洞源于对 参数输入清理和输出转义的不充分。这使得未认证的攻击者可以在页面上注入任意 web 脚本,如果攻击者成功诱使用户执行某些操作(如点击链接),脚本就会执行。 要触发读取 参数的过滤器,WooCommerce 的“添加到购物车后重定向到购物车”选项必须启用;不过,由于 的自动打开机制,除了加载精心
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpclever | WPC Smart Quick View for WooCommerce | ≤ 4.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpclever | WPC Smart Quick View for WooCommerce | 0 ~ 4.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97660 | 7.2 HIGH | WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-104313 | 6.1 MEDIUM | WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via |
No comments yet