<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPC Product Options for WooCommerce (&lt;= 4.0.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpc-product-options-for-woocommerce--4.0.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpc-product-options-for-woocommerce--4.0.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in WPC Product Options for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-10-wpc-xss/</link><pubDate>Sat, 03 Oct 2026 08:54:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wpc-xss/</guid><description>The WPC Product Options for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via improper sanitization of multipart form field names starting with 'wpcpo-'.</description><content:encoded><![CDATA[<p>The WPC Product Options for WooCommerce plugin for WordPress (versions up to and including 4.0.5) contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw stems from insufficient input sanitization and output escaping when processing multipart/form-data requests. Specifically, the plugin fails to sanitize data provided in the Content-Disposition field name when it begins with the 'wpcpo-' prefix.</p>
<p>Because PHP's RFC1867 parser preserves these field names byte-for-byte, an unauthenticated attacker can inject arbitrary JavaScript directly into the order item metadata during a guest checkout session. When an administrator or authorized user views the affected order in the WordPress dashboard, the injected script executes within their browser session. This vulnerability poses a high risk to store integrity and administrative session security, potentially leading to unauthorized actions or account takeover.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the context of a WordPress user's session. This typically impacts store administrators or order managers who view the malicious order details. Potential damage includes unauthorized administrative actions, sensitive data exfiltration, or further compromise of the WordPress environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WPC Product Options for WooCommerce plugin to the latest version immediately.</li>
<li>Monitor web server access logs for POST requests to checkout endpoints containing 'wpcpo-' strings that include unusual characters such as '&lt;', '&gt;', 'script', or 'javascript' in the multipart form field name headers.</li>
<li>Implement a Content Security Policy (CSP) to restrict the execution of inline scripts within the WordPress administrative dashboard.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>