WPC Estimated Delivery Date for WooCommerce(适用于 WordPress 的 WooCommerce 插件)存在反射型跨站脚本(Reflected XSS)漏洞。该漏洞影响所有版本(包括 4.0.1 及以下版本),原因是插件对 'rule_data' 参数缺乏足够的输入清理和输出转义。这使得未认证的攻击者可以向页面中注入任意 Web 脚本,如果攻击者能够诱使用户执行某些操作(例如点击恶意链接),这些脚本将会被执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpclever | WPC Estimated Delivery Date for WooCommerce | 0 ~ 4.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97660 | 7.2 HIGH | WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-103888 | 6.1 MEDIUM | WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq- |
No comments yet