天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-103888 WPC Smart Quick View 反射型 XSS 漏洞

影响攻击者可诱使用户点击链接执行任意脚本

AI 研判

WordPress 插件 WPC Smart Quick View for WooCommerce 存在反射型跨站脚本漏洞,影响 4.4.0 及之前所有版本。漏洞源于对 woosq-redirect 参数输入过滤与输出转义不足,未认证攻击者可注入任意 Web 脚本。

影响范围

WPC Smart Quick View for WooCommerce

WPC Smart Quick View for WooCommerce 插件 4.4.0 及之前所有版本。

漏洞详情

该漏洞属于反射型 XSS,成因是插件未对 woosq-redirect 参数进行充分的输入净化和输出转义。攻击者构造含恶意脚本的 URL,诱使用户访问即可触发执行;需启用 WooCommerce 的“加入购物车后重定向到购物车”选项,且 ?quick-view= 自动打开机制使加载恶意 URL 后无需额外交互即可触发。

利用条件与风险

利用需目标站点启用“加入购物车后重定向到购物车”选项,攻击者通过钓鱼链接诱导用户访问即可在受害者浏览器执行脚本,实战风险中等。

修复建议

建议升级至官方修复版本;临时缓解可禁用“加入购物车后重定向到购物车”选项,或部署 WAF 过滤恶意参数。具体修复版本暂无公开信息。

原始情报

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘woosq-redirect’ parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The WooCommerce “redirect to cart after add to cart” option must be enabled for the filter that reads the woosq-redirect parameter to execute; however, the ?quick-view= auto-open mechanism means no further user interaction beyond loading the crafted URL is required to trigger script execution.