Executive brief
A vulnerability exists in the Min Max Step Quantity Limits Manager for WooCommerce plugin, which is used by online stores to manage product purchase quantities. An attacker can trick a site administrator or customer into clicking a malicious link, allowing the attacker to run unauthorized scripts in their browser. This could lead to the theft of sensitive session information, unauthorized actions performed on behalf of the user, or the defacement of the website.
Technical details
The Min Max Step Quantity Limits Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input in versions up to 5.2.2. An unauthenticated remote attacker can exploit this by sending a specially crafted URL to a user. If the victim clicks the link, the malicious script is executed within the context of their browser session. This vulnerability is classified as CWE-79 and requires user interaction. A patch is available in version 5.2.3.
Affected products
- BeRocket Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2
Timeline
- 2026-02-19: disclosed: Reported by hivesec
- 2026-04-21: advisory: Initial advisory published by Patchstack
- 2026-04-21: patched: Version 5.2.3 released to address the vulnerability
- 2026-06-16: advisory: CVE published in NVD dataset