CVE-2026-104313 Overview
CVE-2026-104313 is a Reflected Cross-Site Scripting (XSS) vulnerability in the WPC Estimated Delivery Date for WooCommerce plugin for WordPress. The flaw affects all versions up to and including 4.0.1. It stems from insufficient input sanitization and output escaping on the rule_data parameter. Unauthenticated attackers can inject arbitrary web scripts that execute when a user clicks a crafted link. Successful exploitation requires user interaction but no authentication. The issue is categorized under CWE-79.
Critical Impact
An unauthenticated attacker can execute arbitrary JavaScript in a victim's browser session, enabling session hijacking, credential theft, or administrative action abuse against authenticated WordPress users.
Affected Products
- WPC Estimated Delivery Date for WooCommerce plugin (WordPress)
- All plugin versions up to and including 4.0.1
- WordPress sites running WooCommerce with this plugin installed
Discovery Timeline
- 2026-10-03 - CVE-2026-104313 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-104313
Vulnerability Analysis
The vulnerability is a reflected XSS flaw in the plugin's rule-handling backend. The rule_data parameter received from HTTP requests is rendered back into administrative pages without proper sanitization or escaping. An attacker crafts a URL containing malicious JavaScript in the rule_data parameter. When a logged-in WordPress user visits the link, the payload executes in their browser under the site's origin. Because the attack chain requires only user interaction and no privileges, the plugin's administrative audience makes this suitable for targeted phishing against site administrators.
Root Cause
The root cause is missing input sanitization on the rule_data parameter and absent output escaping when the value is rendered in the rule.php template. The affected code paths are visible in the plugin's includes/class-backend.php (lines 81 and 385) and includes/templates/rule.php (line 119). WordPress provides sanitization helpers such as sanitize_text_field() and escaping functions like esc_attr() and esc_html() that were not applied to this parameter before output.
Attack Vector
The attack vector is network-based and requires user interaction. An attacker constructs a URL to the vulnerable administrative endpoint with a JavaScript payload in the rule_data query parameter. The attacker delivers the link via phishing email, social media, or an attacker-controlled page. When the targeted WordPress administrator or editor clicks the link while authenticated, the browser renders the reflected payload and executes the script in the context of the WordPress site. See the Wordfence Vulnerability Report and the WordPress Plugin Change Set for the patched implementation.
Detection Methods for CVE-2026-104313
Indicators of Compromise
- HTTP requests to WordPress admin endpoints containing rule_data parameter values with <script>, javascript:, or encoded HTML entities
- Referrer headers from external domains preceding administrative page loads that include rule_data query strings
- Unexpected outbound requests from administrator browser sessions to attacker-controlled domains following plugin page visits
- Creation of new administrator accounts or modification of user roles shortly after suspicious admin page access
Detection Strategies
- Inspect web server access logs for requests containing the rule_data parameter with HTML tags, event handlers (onerror=, onload=), or URL-encoded script content
- Deploy a Web Application Firewall (WAF) rule set to flag reflected XSS patterns targeting WordPress plugin admin endpoints
- Enable WordPress audit logging to capture administrative actions and correlate them with suspicious HTTP referrers
Monitoring Recommendations
- Monitor WordPress plugin inventory to identify installations of WPC Estimated Delivery Date for WooCommerce at version 4.0.1 or earlier
- Alert on anomalous administrator session activity, including unexpected plugin configuration changes or new user creation
- Track external referrers landing on /wp-admin/ pages containing plugin-specific query parameters
How to Mitigate CVE-2026-104313
Immediate Actions Required
- Update the WPC Estimated Delivery Date for WooCommerce plugin to the version released after 4.0.1 that includes the sanitization fix referenced in the plugin change set
- Audit administrator and editor accounts for unexpected changes, new users, or modified roles
- Instruct WordPress administrators to avoid clicking untrusted links while authenticated to the WordPress admin console
Patch Information
The vendor addressed the issue in the version following 4.0.1 by adding input sanitization and output escaping to the rule_data parameter. Review the vendor's commit in the WordPress Plugin Change Set and the affected source files in the WordPress Plugin Template Code. Apply the update through the WordPress plugin management interface or by replacing the plugin files directly.
Workarounds
- Deactivate the WPC Estimated Delivery Date for WooCommerce plugin until the patched version is applied
- Deploy a WAF rule to block or sanitize requests containing HTML or JavaScript syntax in the rule_data parameter
- Enforce a strict Content Security Policy (CSP) on WordPress admin pages to limit inline script execution
- Restrict access to the WordPress administrative interface by source IP where operationally feasible
# Example WAF rule (ModSecurity) to block script payloads in rule_data
SecRule ARGS:rule_data "@rx (?i)(<script|javascript:|onerror=|onload=)" \
"id:1041313,phase:2,deny,status:403,msg:'CVE-2026-104313 Reflected XSS attempt in rule_data parameter'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.