PT-2026-104502 · WordPress · Wpc Smart Quick View For Woocommerce
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPC Smart Quick View for WooCommerce versions prior to 4.4.1
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs via the
woosq-redirect parameter, enabling the injection of arbitrary web scripts that execute when a user loads a crafted URL. The issue requires the WooCommerce redirect to cart after add to cart option to be enabled, though the ?quick-view= auto-open mechanism allows script execution without further user interaction beyond loading the URL.Recommendations
Update WPC Smart Quick View for WooCommerce to version 4.4.1 or later.
Avoid using the
woosq-redirect parameter in the affected plugin until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpc Smart Quick View For Woocommerce