CVE-2026-103888: WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter

Published Oct 3, 2026
·
Updated

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The WooCommerce "redirect to cart after add to cart" option must be enabled for the filter that reads the woosq-redirect parameter to execute; however, the ?quick-view= auto-open mechanism means no further user interaction beyond loading the crafted URL is required to trigger script execution.

Affected Software

1 affected component
WPClever WPC Smart Quick View for WooCommerce<=4.4.0

Event History

Oct 3, 2026
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What configuration is required for this issue to be exploitable?

The WooCommerce “redirect to cart after add to cart” option must be enabled, because the affected filter reads the woosq-redirect parameter only in that configuration.

2

Does exploitation require an attacker to authenticate or a victim to interact with the site after opening the link?

No attacker authentication is required. Although an attacker must deliver a crafted URL to a victim, the ?quick-view= auto-open mechanism can trigger script execution when the URL loads, without further victim interaction.

3

Who is exposed?

Sites running WPC Smart Quick View for WooCommerce version 4.4.0 or earlier are affected when the required WooCommerce redirect-to-cart setting is enabled. Visitors who load an attacker-crafted URL may be exposed to injected scripts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203