Description
The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-10-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The WPC Estimated Delivery Date for WooCommerce plugin contains an unsanitized 'rule_data' parameter that allows reflected cross‑site scripting. An attacker can inject JavaScript that runs in a victim’s browser when the victim follows a crafted link or performs an action that includes the malicious parameter. This vulnerability can be abused to steal session data, deface the site, or execute further malicious payloads.

Affected Systems

All WordPress sites running the WPclever WPC Estimated Delivery Date plugin version 4.0.1 or earlier are affected. The issue exists in every released version up to including 4.0.1 of the plugin.

Risk and Exploitability

The CVSS score of 6.1 places the flaw in the medium severity range. EPSS information is not available and the vulnerability is not listed in the KEV catalog, indicating no known widespread exploitation at this time. The attack vector is inferred to be an unauthenticated, social‑engineering approach where the attacker supplies a crafted 'rule_data' value in a link that a victim clicks. The vulnerability requires no privileged access and relies solely on improper input validation, so the attack can be performed from any external address. Although the exploit is relatively simple, it needs a target user to engage with the malicious link, making the overall exploitation probability moderate.

Generated by OpenCVE AI on October 3, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPC Estimated Delivery Date plugin to the latest released version that contains the XSS fix.
  • If an update is not immediately feasible, deactivate or uninstall the plugin until a patched version is available.
  • Apply a web‑application firewall rule or implement a Content Security Policy that prevents execution of untrusted scripts on rendered pages.

Generated by OpenCVE AI on October 3, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via 'rule_data' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.487Z

Reserved: 2026-10-01T19:40:47.822Z

Link: CVE-2026-104313

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:40.705Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:47.210

Modified: 2026-10-03T16:16:34.573

Link: CVE-2026-104313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')