Junglewise Threat Intelligence

CVE-2026-59512: PI Web Solution Product Enquiry for WooCommerce unauthenticated XSS

CVE-2026-59512 · Severity: high · CVSS 7.1 · Published 2026-07-23

Executive brief

The Product Enquiry for WooCommerce plugin, which allows customers to ask questions about products on e-commerce sites, contains a security flaw that allows attackers to inject malicious scripts. If an administrator or another user views a specially crafted enquiry, the attacker's script could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This vulnerability can be exploited by anyone on the internet without needing an account on the affected website.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Product Enquiry for WooCommerce plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into the application. Successful exploitation requires a victim (typically a site administrator) to interact with a malicious link or view a crafted enquiry. This can lead to session hijacking, unauthorized administrative actions, or website defacement. The issue is resolved in version 2.2.34.44.

Affected products

  • PI Web Solution Product Enquiry for WooCommerce <= 2.2.34.43

Timeline

  • 2026-07-01: other: Reported by researcher duna
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References