Vendor
The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored XSS via the 'qty' parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of administrative or user sessions.