Junglewise Threat Intelligence

CVE-2026-2838: idealwebdesignlk Whole Enquiry Cart for WooCommerce Stored XSS

CVE-2026-2838 · Severity: medium · CVSS 4.4 · Published 2026-04-08

Executive brief

The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to a security flaw that allows administrators to inject malicious scripts into the website. This issue primarily affects WordPress multi-site environments or specific configurations where standard security restrictions on HTML content have been disabled. If exploited, an attacker could run unauthorized code in the browsers of other users, potentially leading to unauthorized actions or data theft.

Technical details

The Whole Enquiry Cart for WooCommerce plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization and output escaping on the 'woowhole_success_msg' parameter. An authenticated attacker with administrator-level privileges can inject arbitrary web scripts into the database. These scripts then execute in the context of any user's browser who visits the affected page. This vulnerability is specifically exploitable in WordPress multi-site installations or environments where the 'unfiltered_html' capability has been restricted. The issue exists in all versions up to and including 1.2.1.

Affected products

  • idealwebdesignlk Whole Enquiry Cart for WooCommerce <= 1.2.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References