Skip to main content
Vulnerability Database/CVE-2026-104313

CVE-2026-104313: WPC Estimated Delivery Date XSS Vulnerability

CVE-2026-104313 is a reflected cross-site scripting flaw in WPC Estimated Delivery Date for WooCommerce that allows attackers to inject malicious scripts. This post covers its technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-104313 Overview

CVE-2026-104313 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WPC Estimated Delivery Date for WooCommerce plugin for WordPress. The flaw affects all versions up to and including 4.0.1. It stems from insufficient input sanitization and output escaping on the rule_data parameter. Unauthenticated attackers can inject arbitrary web scripts that execute when a user clicks a crafted link. Successful exploitation requires user interaction but no authentication. The issue is categorized under CWE-79.

Critical Impact

An unauthenticated attacker can execute arbitrary JavaScript in a victim's browser session, enabling session hijacking, credential theft, or administrative action abuse against authenticated WordPress users.

Affected Products

  • WPC Estimated Delivery Date for WooCommerce plugin (WordPress)
  • All plugin versions up to and including 4.0.1
  • WordPress sites running WooCommerce with this plugin installed

Discovery Timeline

  • 2026-10-03 - CVE-2026-104313 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-104313

Vulnerability Analysis

The vulnerability is a reflected XSS flaw in the plugin's rule-handling backend. The rule_data parameter received from HTTP requests is rendered back into administrative pages without proper sanitization or escaping. An attacker crafts a URL containing malicious JavaScript in the rule_data parameter. When a logged-in WordPress user visits the link, the payload executes in their browser under the site's origin. Because the attack chain requires only user interaction and no privileges, the plugin's administrative audience makes this suitable for targeted phishing against site administrators.

Root Cause

The root cause is missing input sanitization on the rule_data parameter and absent output escaping when the value is rendered in the rule.php template. The affected code paths are visible in the plugin's includes/class-backend.php (lines 81 and 385) and includes/templates/rule.php (line 119). WordPress provides sanitization helpers such as sanitize_text_field() and escaping functions like esc_attr() and esc_html() that were not applied to this parameter before output.

Attack Vector

The attack vector is network-based and requires user interaction. An attacker constructs a URL to the vulnerable administrative endpoint with a JavaScript payload in the rule_data query parameter. The attacker delivers the link via phishing email, social media, or an attacker-controlled page. When the targeted WordPress administrator or editor clicks the link while authenticated, the browser renders the reflected payload and executes the script in the context of the WordPress site. See the Wordfence Vulnerability Report and the WordPress Plugin Change Set for the patched implementation.

Detection Methods for CVE-2026-104313

Indicators of Compromise

  • HTTP requests to WordPress admin endpoints containing rule_data parameter values with <script>, javascript:, or encoded HTML entities
  • Referrer headers from external domains preceding administrative page loads that include rule_data query strings
  • Unexpected outbound requests from administrator browser sessions to attacker-controlled domains following plugin page visits
  • Creation of new administrator accounts or modification of user roles shortly after suspicious admin page access

Detection Strategies

  • Inspect web server access logs for requests containing the rule_data parameter with HTML tags, event handlers (onerror=, onload=), or URL-encoded script content
  • Deploy a Web Application Firewall (WAF) rule set to flag reflected XSS patterns targeting WordPress plugin admin endpoints
  • Enable WordPress audit logging to capture administrative actions and correlate them with suspicious HTTP referrers

Monitoring Recommendations

  • Monitor WordPress plugin inventory to identify installations of WPC Estimated Delivery Date for WooCommerce at version 4.0.1 or earlier
  • Alert on anomalous administrator session activity, including unexpected plugin configuration changes or new user creation
  • Track external referrers landing on /wp-admin/ pages containing plugin-specific query parameters

How to Mitigate CVE-2026-104313

Immediate Actions Required

  • Update the WPC Estimated Delivery Date for WooCommerce plugin to the version released after 4.0.1 that includes the sanitization fix referenced in the plugin change set
  • Audit administrator and editor accounts for unexpected changes, new users, or modified roles
  • Instruct WordPress administrators to avoid clicking untrusted links while authenticated to the WordPress admin console

Patch Information

The vendor addressed the issue in the version following 4.0.1 by adding input sanitization and output escaping to the rule_data parameter. Review the vendor's commit in the WordPress Plugin Change Set and the affected source files in the WordPress Plugin Template Code. Apply the update through the WordPress plugin management interface or by replacing the plugin files directly.

Workarounds

  • Deactivate the WPC Estimated Delivery Date for WooCommerce plugin until the patched version is applied
  • Deploy a WAF rule to block or sanitize requests containing HTML or JavaScript syntax in the rule_data parameter
  • Enforce a strict Content Security Policy (CSP) on WordPress admin pages to limit inline script execution
  • Restrict access to the WordPress administrative interface by source IP where operationally feasible
bash
# Example WAF rule (ModSecurity) to block script payloads in rule_data
SecRule ARGS:rule_data "@rx (?i)(<script|javascript:|onerror=|onload=)" \
    "id:1041313,phase:2,deny,status:403,msg:'CVE-2026-104313 Reflected XSS attempt in rule_data parameter'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.