{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpcleverwpc_product_bundles_for_woocommercewordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpclever:wpc_product_bundles_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPC Product Bundles for WooCommerce (\u003c= 8.6.6)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WPClever"],"content_html":"\u003cp\u003eThe WPC Product Bundles for WooCommerce plugin (all versions up to and including 8.6.6) contains a critical Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-93836. The vulnerability stems from insufficient input sanitization of the 'qty' parameter. Although the plugin performs a float cast validation for the quantity input, this mechanism is flawed; it allows numeric-prefixed payloads such as \u0026quot;1\u0026lt;img src=x onerror=alert(1)\u0026gt;\u0026quot; to pass validation while preserving the malicious HTML content.\u003c/p\u003e\n\u003cp\u003eThis malicious payload is subsequently stored in the database within order item metadata under the '_woosb_ids' key. When an administrator or authorized user views the compromised order details page within the WordPress dashboard, the injected script executes in their browser session. This vulnerability poses a significant risk as it permits unauthenticated attackers to perform actions on behalf of privileged users, potentially leading to full site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. If the victim is an administrator, this can lead to unauthorized administrative actions, account takeover, or the installation of malicious plugins. This affects any WordPress environment utilizing WPC Product Bundles for WooCommerce version 8.6.6 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPC Product Bundles for WooCommerce plugin to a version released after 8.6.6 that addresses CVE-2026-93836.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall logs for requests targeting WooCommerce endpoints containing HTML tags or script injection patterns within the 'qty' parameter.\u003c/li\u003e\n\u003cli\u003eAudit existing WooCommerce order metadata for entries containing suspicious HTML tags or script attributes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T08:35:00Z","date_published":"2026-09-22T08:35:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wpc-xss/","summary":"The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored XSS via the 'qty' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative or user sessions.","title":"Stored Cross-Site Scripting in WPC Product Bundles for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-09-wpc-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpclever:wpc_product_bundles_for_woocommerce:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}