Sceawere
Vulnerability Detail
CVE-2026-104313UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in WPC Estimated Delivery Date
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- wpclever
- Product
- WPC Estimated Delivery Date for WooCommerce
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-03T07:16:47.210Z",
"pubdate": "2026-10-03T07:16:47.210Z",
"executiveSummary": "The WPC Estimated Delivery Date plugin for WooCommerce is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. Identified in all versions up to and including 4.0.1, the flaw stems from improper handling of user-supplied input within the 'rule_data' parameter.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary JavaScript within the context of a victim's browser session. By crafting a malicious URL containing a payload in the 'rule_data' parameter, an attacker can trick an authenticated user into clicking a link, triggering the execution of unauthorized scripts.\nThe impact of this vulnerability is significant, as successful exploitation may lead to session hijacking, unauthorized actions performed on behalf of the victim, or the theft of sensitive session cookies. Because the injection is reflected, the malicious payload is delivered via the application's response, making social engineering a primary vector. Organizations utilizing this plugin are advised to restrict access or apply updates immediately upon availability to mitigate the risk of client-side code injection and potential account compromise.",
"technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw located within the WPC Estimated Delivery Date for WooCommerce plugin. The root cause is the insufficient sanitization of user-supplied data and the failure to perform proper output escaping when processing the 'rule_data' parameter before rendering it back to the end-user's browser.\nThe affected component fails to validate the input provided through the HTTP request, allowing an attacker to inject arbitrary HTML and JavaScript tags. Because the application reflects this input directly into the HTML document, the browser interprets the payload as legitimate code belonging to the web application.\nThe attack flow proceeds as follows: First, the attacker identifies the 'rule_data' parameter as a vector for input reflection. Second, the attacker crafts a malicious URI containing a script payload, such as '<script>alert(document.cookie)</script>', within this parameter. Third, the attacker distributes this link to a target user, typically an administrator or a privileged user, through social engineering tactics. When the victim clicks the link, the server processes the request and embeds the malicious script into the HTTP response. Finally, the victim's browser, receiving the response, parses and executes the injected script within the security context of the vulnerable WordPress site.\nThe exploitation does not require prior authentication, as the vulnerable endpoint is accessible to unauthenticated remote attackers. The payload executes with the privileges of the victim's session, effectively bypassing standard server-side security controls. Post-exploitation impact is severe, potentially allowing an attacker to gain unauthorized access to administrative functions, manipulate displayed content, redirect users to malicious third-party domains, or exfiltrate session identifiers (such as authentication cookies) to establish persistent unauthorized access. Given the reflected nature of the vulnerability, the payload remains non-persistent on the server, but the immediate threat to the victim's local session remains critical."
}