Impact
The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to a stored cross‑site scripting flaw that allows an unauthenticated attacker to inject arbitrary JavaScript. The vulnerability arises from insufficient sanitization and escaping of the multipart Content‑Disposition field name beginning with "wpcpo-". When this payload is submitted through guest checkout, the field name is preserved exactly by the PHP RFC1867 parser and stored in order item metadata, later served in backend pages as part of the order interface. An attacker can therefore have arbitrary scripts executed in the browsers of any administrator or other user who views the affected page, potentially leading to session hijacking, credential theft, defacement, or post‑exploitation activities.
Affected Systems
The flaw affects the WordPress plugin "WPC Product Options for WooCommerce" supplied by the wpclever vendor. All plugin releases up to and including version 4.0.5 are vulnerable. No later version has been confirmed in the supplied data.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is most likely guest checkout flows that accept multipart form data without authentication. An attacker can exploit the stored payload without needing credentials, and the effect is confined to the browsers of users who view the stored data.
OpenCVE Enrichment