{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpc-product-options-for-woocommerce--4.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpclever:wpc_product_options_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-97660"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPC Product Options for WooCommerce (\u003c= 4.0.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WPClever"],"content_html":"\u003cp\u003eThe WPC Product Options for WooCommerce plugin for WordPress (versions up to and including 4.0.5) contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from insufficient input sanitization and output escaping when processing multipart/form-data requests. Specifically, the plugin fails to sanitize data provided in the Content-Disposition field name when it begins with the 'wpcpo-' prefix.\u003c/p\u003e\n\u003cp\u003eBecause PHP's RFC1867 parser preserves these field names byte-for-byte, an unauthenticated attacker can inject arbitrary JavaScript directly into the order item metadata during a guest checkout session. When an administrator or authorized user views the affected order in the WordPress dashboard, the injected script executes within their browser session. This vulnerability poses a high risk to store integrity and administrative session security, potentially leading to unauthorized actions or account takeover.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the context of a WordPress user's session. This typically impacts store administrators or order managers who view the malicious order details. Potential damage includes unauthorized administrative actions, sensitive data exfiltration, or further compromise of the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPC Product Options for WooCommerce plugin to the latest version immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for POST requests to checkout endpoints containing 'wpcpo-' strings that include unusual characters such as '\u0026lt;', '\u0026gt;', 'script', or 'javascript' in the multipart form field name headers.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) to restrict the execution of inline scripts within the WordPress administrative dashboard.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T08:54:56Z","date_published":"2026-10-03T08:54:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpc-xss/","summary":"The WPC Product Options for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via improper sanitization of multipart form field names starting with 'wpcpo-'.","title":"Stored XSS in WPC Product Options for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-10-wpc-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - WPC Product Options for WooCommerce (\u003c= 4.0.5)","version":"https://jsonfeed.org/version/1.1"}