CPE
The WPC Product Options for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via improper sanitization of multipart form field names starting with 'wpcpo-'.