Skip to content
Threat Feed
high advisory

Stored XSS in WPC Product Options for WooCommerce

The WPC Product Options for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via improper sanitization of multipart form field names starting with 'wpcpo-'.

CVE search metadata

CVE search record: CVE-2026-97660. Severity: high. CVSS: 7.2. KEV: no. Product: WPC Product Options for WooCommerce (<= 4.0.5). Brief: Stored XSS in WPC Product Options for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wpc-xss/

The WPC Product Options for WooCommerce plugin for WordPress (versions up to and including 4.0.5) contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from insufficient input sanitization and output escaping when processing multipart/form-data requests. Specifically, the plugin fails to sanitize data provided in the Content-Disposition field name when it begins with the 'wpcpo-' prefix.

Because PHP's RFC1867 parser preserves these field names byte-for-byte, an unauthenticated attacker can inject arbitrary JavaScript directly into the order item metadata during a guest checkout session. When an administrator or authorized user views the affected order in the WordPress dashboard, the injected script executes within their browser session. This vulnerability poses a high risk to store integrity and administrative session security, potentially leading to unauthorized actions or account takeover.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the context of a WordPress user's session. This typically impacts store administrators or order managers who view the malicious order details. Potential damage includes unauthorized administrative actions, sensitive data exfiltration, or further compromise of the WordPress environment.

Recommendation

  • Update the WPC Product Options for WooCommerce plugin to the latest version immediately.
  • Monitor web server access logs for POST requests to checkout endpoints containing 'wpcpo-' strings that include unusual characters such as '<', '>', 'script', or 'javascript' in the multipart form field name headers.
  • Implement a Content Security Policy (CSP) to restrict the execution of inline scripts within the WordPress administrative dashboard.

Immediate actions

Upgrade WPC Product Options for WooCommerce to a version greater than 4.0.5

IT Operations 48h

Threat Hunt

Search web logs for POST requests to checkout pages with multipart field names containing suspicious characters

T1190 medium medium confidence hunt now

Data: Web server logs (POST /checkout, etc)

Mitigations

Upgrade vulnerable plugin

immediate IT Operations

CVE-2026-97660