CVE-2026-103888 Overview
CVE-2026-103888 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WPC Smart Quick View for WooCommerce WordPress plugin. The flaw affects all plugin versions up to and including 4.4.0. It stems from insufficient input sanitization and output escaping on the woosq-redirect URL parameter. Unauthenticated attackers can craft a URL that executes arbitrary JavaScript in a victim's browser when the link is loaded. The ?quick-view= auto-open mechanism removes the need for further interaction beyond visiting the crafted URL. Exploitation requires the WooCommerce "redirect to cart after add to cart" option to be enabled.
Critical Impact
Unauthenticated attackers can execute arbitrary scripts in victim browsers, enabling session theft, credential harvesting, and administrative account takeover on affected WooCommerce stores.
Affected Products
- WPC Smart Quick View for WooCommerce plugin versions ≤ 4.4.0
- WordPress sites running WooCommerce with the vulnerable plugin installed
- WooCommerce stores with "redirect to cart after add to cart" enabled
Discovery Timeline
- 2026-10-03 - CVE-2026-103888 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-103888
Vulnerability Analysis
The vulnerability is a Reflected Cross-Site Scripting flaw classified under [CWE-79]. The WPC Smart Quick View plugin reads the woosq-redirect query parameter and reflects its value into page output without proper sanitization or escaping. When a victim loads a crafted URL, injected JavaScript executes in the browser under the origin of the affected WooCommerce store. Successful exploitation can lead to session hijacking, forced actions on behalf of authenticated users, phishing content injection, and administrative account compromise if a logged-in administrator clicks the link.
Root Cause
The root cause lies in how the plugin handles the woosq-redirect parameter. The responsible filter reads the user-supplied value and emits it into rendered HTML or JavaScript context without applying WordPress sanitization helpers such as esc_url(), esc_attr(), or esc_html(). Relevant code paths exist in wpc-smart-quick-view.php around lines 221 and 1372, and in assets/js/frontend.js around line 98. The filter that reads woosq-redirect only executes when the WooCommerce "redirect to cart after add to cart" option is enabled.
Attack Vector
The attack vector is network-based and requires minimal user interaction. An attacker crafts a URL containing a malicious payload in the woosq-redirect parameter together with a quick-view= value that triggers the auto-open mechanism. The attacker delivers the link through phishing email, social media, forum posts, or a malicious ad. When the victim loads the URL on the vulnerable site, the quick-view modal opens automatically and the injected script executes. No clicks inside the page are required beyond loading the URL. See the Wordfence Vulnerability Report and the WordPress Plugin Changeset for technical details.
Detection Methods for CVE-2026-103888
Indicators of Compromise
- HTTP requests containing the woosq-redirect query parameter with values that include <script>, javascript:, onerror=, or encoded script delimiters
- Requests combining ?quick-view= with suspicious woosq-redirect content from external referrers
- Access log entries where unauthenticated clients deliver long or URL-encoded payloads to product pages
- Unexpected outbound requests from administrator browsers immediately after visiting product URLs
Detection Strategies
- Deploy Web Application Firewall (WAF) rules that inspect the woosq-redirect parameter for HTML and JavaScript metacharacters
- Enable Content Security Policy (CSP) reporting to capture inline script violations originating from product pages
- Correlate referrer headers with sudden spikes in requests to WooCommerce quick-view endpoints
- Monitor for anomalous administrator session activity following access to crafted product URLs
Monitoring Recommendations
- Centralize WordPress access and error logs for query-string analysis
- Alert on any request where woosq-redirect contains URL-encoded tag characters such as %3C, %3E, or %22
- Track plugin version inventory across WordPress estates to identify installations at or below 4.4.0
- Review browser telemetry on administrator endpoints for unexpected script execution on store domains
How to Mitigate CVE-2026-103888
Immediate Actions Required
- Update the WPC Smart Quick View for WooCommerce plugin to the latest version above 4.4.0 as soon as the vendor patch is available
- Audit WordPress sites to identify all installations of the vulnerable plugin
- Rotate administrator credentials and invalidate active sessions if exploitation is suspected
- Deploy WAF rules to block requests containing script payloads in the woosq-redirect parameter
Patch Information
Review the WordPress Plugin Changeset and the Wordfence Vulnerability Report for remediation guidance. Site administrators should update the plugin through the WordPress admin dashboard once a fixed release is published.
Workarounds
- Temporarily disable the WPC Smart Quick View for WooCommerce plugin until a patched version is installed
- Disable the WooCommerce "redirect to cart after add to cart" option, which prevents the vulnerable filter from executing
- Implement a strict Content Security Policy that disallows inline scripts on store pages
- Restrict administrator access to the site from a limited set of trusted networks
# Example WAF rule concept to block script payloads in woosq-redirect
# ModSecurity-style pseudo-rule
SecRule ARGS:woosq-redirect "@rx (?i)(<script|javascript:|onerror=|onload=|%3Cscript)" \
"id:1038880,phase:2,deny,status:403,log,msg:'CVE-2026-103888 woosq-redirect XSS attempt'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.