Impact
The WPC Smart Quick View for WooCommerce plugin allows attackers to inject arbitrary JavaScript through the unscrutinized 'woosq-redirect' parameter. When a visitor opens a crafted URL, the plugin processes the parameter and outputs its value into the page without escaping it, enabling a reflected cross‑site scripting attack. Successful exploitation lets an attacker run code in the victim’s browser, potentially stealing cookies, session data, or defacing the site. The vulnerability is exploitable by unauthenticated users and does not require privileged credentials.
Affected Systems
All versions of the wpclever WPC Smart Quick View for WooCommerce plugin up to and including 4.4.0 are affected. No specific sub‑versions are listed beyond the upper bound.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, so the actual exploitation probability is unknown, but the flaw is listed outside of the CISA KEV catalog. Attackers can reach the vulnerable parameter via a crafted URL, and the WooCommerce setting "redirect to cart after add to cart" must be enabled for the payload to be processed. Because the "auto‑open" quick‑view mechanism triggers the vulnerable code without further user interaction, a single click on the malicious link is sufficient to trigger script execution.
OpenCVE Enrichment