CVE-2026-103888: WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The WooCommerce "redirect to cart after add to cart" option must be enabled for the filter that reads the woosq-redirect parameter to execute; however, the ?quick-view= auto-open mechanism means no further user interaction beyond loading the crafted URL is required to trigger script execution.
Affected Software
Event History
Frequently Asked Questions
What configuration is required for this issue to be exploitable?
The WooCommerce “redirect to cart after add to cart” option must be enabled, because the affected filter reads the woosq-redirect parameter only in that configuration.
Does exploitation require an attacker to authenticate or a victim to interact with the site after opening the link?
No attacker authentication is required. Although an attacker must deliver a crafted URL to a victim, the ?quick-view= auto-open mechanism can trigger script execution when the URL loads, without further victim interaction.
Who is exposed?
Sites running WPC Smart Quick View for WooCommerce version 4.4.0 or earlier are affected when the required WooCommerce redirect-to-cart setting is enabled. Visitors who load an attacker-crafted URL may be exposed to injected scripts.