What is CVE-2026-93836?
The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' parameter in all versions up to, and including, 8.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The float cast used during quantity validation allows a numeric-prefixed payload such as '1<img src=x onerror=...>' to pass validation while retaining its malicious HTML, which is then stored verbatim in order item metadata under the '_woosb_ids' key.
Timeline
- 2026-09-22Published to the U.S. National Vulnerability Database (NVD)
- 2026-10-07First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Apply the vendor security update for Ninja Forms (WordPress plugin) as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References
- https://plugins.trac.wordpress.org/browser/woo-product-bundle/tags/8.6.5/includes/class-backend.php#L1949
- https://plugins.trac.wordpress.org/browser/woo-product-bundle/tags/8.6.5/includes/class-woosb.php#L1197
- https://plugins.trac.wordpress.org/browser/woo-product-bundle/tags/8.6.5/includes/class-woosb.php#L579
- https://nvd.nist.gov/vuln/detail/CVE-2026-93836
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of October 2026 (October 5 – 11)
- WordPress, Atlassian, ASOS breached; AI-powered phishing escalates (2026-10-07)
Browse all tracked CVEs in the defend.network CVE database →