PT-2026-104502 · WordPress · Wpc Smart Quick View For Woocommerce

·

CVE-2026-103888

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPC Smart Quick View for WooCommerce versions prior to 4.4.1
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs via the woosq-redirect parameter, enabling the injection of arbitrary web scripts that execute when a user loads a crafted URL. The issue requires the WooCommerce redirect to cart after add to cart option to be enabled, though the ?quick-view= auto-open mechanism allows script execution without further user interaction beyond loading the URL.
Recommendations Update WPC Smart Quick View for WooCommerce to version 4.4.1 or later. Avoid using the woosq-redirect parameter in the affected plugin until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103888

Affected Products

Wpc Smart Quick View For Woocommerce