CVE-2026-97660 Overview
CVE-2026-97660 is a stored Cross-Site Scripting (XSS) vulnerability in the WPC Product Options for WooCommerce plugin for WordPress. The flaw affects all versions up to and including 4.0.5. Unauthenticated attackers can inject arbitrary web scripts via a crafted multipart Content-Disposition field name beginning with wpcpo-. The payload is preserved byte-for-byte by PHP's RFC1867 multipart parser and persisted into order item meta. Scripts execute when a user, typically an administrator reviewing orders, accesses the affected page.
Critical Impact
Unauthenticated attackers can store JavaScript payloads via guest checkout. The injected scripts execute in administrator browsers reviewing orders, enabling session hijacking, privilege abuse, and backend takeover of WooCommerce stores.
Affected Products
- WPC Product Options for WooCommerce plugin for WordPress
- All plugin versions up to and including 4.0.5
- WordPress sites running WooCommerce with the vulnerable plugin enabled
Discovery Timeline
- 2026-10-03 - CVE-2026-97660 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-97660
Vulnerability Analysis
The vulnerability is a stored XSS flaw categorized under [CWE-79]. The plugin accepts user-controlled input through multipart form fields during the WooCommerce checkout flow. Field names prefixed with wpcpo- are enumerated and copied into cart item data without sanitization or output escaping. The injected content is later stored in order item meta and rendered in administrative interfaces. Because the attack vector traverses guest checkout, no authentication is required to deliver the payload.
Root Cause
The plugin trusts the multipart Content-Disposition field name as a safe identifier. PHP's RFC1867 parser preserves the raw bytes of the field name, including HTML special characters. Code paths in includes/class-cart.php (lines 336, 537, 573, 579, and 792) iterate over wpcpo-* keys and persist them without applying sanitize_text_field(), esc_html(), or equivalent escaping on output. The absence of both input filtering and context-aware output encoding allows raw HTML and JavaScript to reach the DOM.
Attack Vector
An unauthenticated attacker submits a crafted multipart checkout request. The attacker places a JavaScript payload inside the name attribute of a form field whose name begins with wpcpo-. WooCommerce processes the guest checkout, and the plugin writes the attacker-controlled key into order item meta. When a store administrator opens the order in the WordPress admin panel, the stored script executes in the administrator's authenticated session. See the Wordfence Vulnerability Analysis and the WordPress Changeset Overview for technical references.
No verified proof-of-concept code is available in the referenced sources. Review the plugin source at class-cart.php line 336 for the affected code path.
Detection Methods for CVE-2026-97660
Indicators of Compromise
- Order item meta entries containing HTML tags, <script> fragments, or on*= event handler attributes within keys prefixed by wpcpo-.
- Unusual guest checkout requests with multipart Content-Disposition field names containing angle brackets or JavaScript keywords.
- Administrator sessions exhibiting unexpected outbound requests shortly after viewing WooCommerce order pages.
Detection Strategies
- Inspect the wp_woocommerce_order_itemmeta table for meta_key values beginning with wpcpo- that contain HTML markup or scripting syntax.
- Monitor web server access logs for POST requests to WooCommerce checkout endpoints containing suspicious multipart field names.
- Deploy a Web Application Firewall rule to flag multipart form submissions where name="wpcpo-..." contains <, >, or javascript:.
Monitoring Recommendations
- Alert on new or modified administrator accounts, option changes, or plugin installations following administrator access to order pages.
- Enable WordPress audit logging to correlate order views with privileged backend actions.
- Track browser-side Content Security Policy (CSP) violation reports on /wp-admin/ pages.
How to Mitigate CVE-2026-97660
Immediate Actions Required
- Disable the WPC Product Options for WooCommerce plugin until a patched version is deployed and verified.
- Audit existing WooCommerce orders for malicious wpcpo-* meta keys and remove tainted entries.
- Rotate administrator credentials and invalidate active sessions if administrators have viewed orders during the exposure window.
Patch Information
The vendor committed a fix tracked under WordPress plugin changeset 3712354. Upgrade to the first plugin release that supersedes version 4.0.5 and includes the referenced changeset. Verify the installed version in the WordPress admin plugins page after update.
Workarounds
- Deploy a WAF rule blocking multipart form fields whose name attribute matches wpcpo-.*[<>"'].
- Restrict access to /wp-admin/ and WooCommerce order management pages by source IP where feasible.
- Enforce a strict Content Security Policy on WordPress administrative pages to limit inline script execution.
# Example ModSecurity rule to block malicious wpcpo-* multipart field names
SecRule REQUEST_HEADERS:Content-Type "@contains multipart/form-data" \
"chain,id:1009766,phase:2,deny,status:403,log,msg:'CVE-2026-97660 wpcpo-* XSS attempt'"
SecRule REQUEST_BODY "@rx name=\"wpcpo-[^\"]*[<>][^\"]*\"" "t:none"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.