AI analysis
The WPC Product Bundles for WooCommerce plugin for WordPress contains a stored cross-site scripting vulnerability in all versions up to and including 8.6.6, caused by insufficient sanitization of the 'qty' parameter. Because quantity validation uses a float cast, a numeric-prefixed script payload can pass the check while its malicious HTML survives intact and is stored verbatim in order item metadata under the '_woosb_ids' key. An unauthenticated attacker can exploit this by submitting a crafted bundle quantity, and the injected script executes in the browser of any user — including store staff or administrators — who views the affected page or order. Any site running the plugin at or below version 8.6.6 with WooCommerce is affected. No public proof of concept is known and the flaw is not on the CISA KEV catalog, so exploitation is not currently observed.
What to do: Update to the latest version of WPC Product Bundles for WooCommerce (anything newer than 8.6.6) as soon as a patched release is available. Audit order item metadata for the '_woosb_ids' key and look for numeric-prefixed values containing unexpected HTML or script tags, and remove any found entries. Until patched, apply a WAF rule blocking HTML/script characters in 'qty' parameters on bundle add-to-cart requests, and remind admins to view orders only in sanitized contexts.
Affected
| WPClever WPC Product Bundles for WooCommerce (WordPress plugin) | All versions up to and including 8.6.6 |
Estimated exposure
large≈30,000–40,000 WooCommerce sites (tens of thousands of active installs) — The plugin is a popular WooCommerce bundling extension with tens of thousands of active installs reported on WordPress.org, and most WooCommerce storefronts are public-facing, so the majority of those installations are plausibly reachable…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float cast used during quantity validation allows a numeric-prefixed payload such as '1 ' to pass validation while retaining its malicious HTML, which is then stored verbatim in order item metadata under the '_woosb_ids' key.