
CVE-2026-2838 The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘woowhole_success_msg’ parameter in all versions up to,… https://www.cve.org/CVERecord?id=CVE-2026-2838
Post summary
A new WordPress WooCommerce plugin vulnerability (CVE‑2026‑2838) has been identified as stored XSS via a specific parameter; no PoC, exploit code, or patch details are provided.
