VYPR

WPC Estimated Delivery Date for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-104313MedOct 3, 2026
    risk 0.40cvss 6.1epss —

    The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for…