Junglewise Threat Intelligence

CVE-2026-57414: QuantumCloud WoowBot Stored XSS in eCommerce ChatBot

CVE-2026-57414 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Vendors: QuantumCloud.

Executive brief

QuantumCloud WoowBot, a chatbot plugin for WordPress eCommerce sites, contains a security flaw that allows attackers to inject malicious scripts. If an attacker with basic user access tricks a site administrator into viewing a specific page, they could potentially hijack administrative sessions or redirect customers to fraudulent websites. This could lead to unauthorized access to the store's management interface or the theft of customer information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the QuantumCloud ChatBot for eCommerce – WoowBot plugin for WordPress (versions up to and including 4.6.1). The issue stems from improper neutralization of user-supplied input during web page generation. An attacker with 'Subscriber' level privileges can inject malicious scripts into the application, which are then stored and executed in the context of a more privileged user's browser (such as an administrator) when they interact with the affected component. This is classified as CWE-79 and has been addressed in version 4.7.0.

Affected products

  • QuantumCloud ChatBot for eCommerce – WoowBot <= 4.6.1

Timeline

  • 2026-05-17: disclosed: Reported by ParkHyunWoo
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published CVE-2026-57414
  • 2026-07-08: patched: Version 4.7.0 released to address the issue

References