CVE-2026-59512

WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.


We have discovered 301 live websites that are affected by CVE-2026-59512.

Run a Free Instant Scan




Affected Software

Product  Enquiry Quotation For Woocommerce
Category Wordpress Plugins
Vulnerable Domains301 live websites (100% of Enquiry Quotation For Woocommerce install base)
Vulnerable Versions
  • from 0 through 2.2.34.43
Vulnerable Versions Count48 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • duna | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-59512
United States53 websites



India32 websites
Germany23 websites
GB21 websites
Singapore17 websites
South Africa16 websites
Australia14 websites
Cyprus14 websites
Poland12 websites
Hong Kong7 websites

Website Distribution by TLD

Number of websites using CVE-2026-59512
.com140 websites
.co.uk14 websites
.com.au13 websites
.pl9 websites
.de5 websites
.net5 websites
.ru4 websites
.org3 websites
.com.br3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59512

Top websites that are affected by CVE-2026-59512. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***,***
********.com United States*,***,***
**************.com GB*,***,***
********.com Hong Kong*,***,***
************.com GB*,***,***
********.**.kr Korea, South*,***,***
*********.**.uk GB*,***,***
******.**.za South Africa*,***,***
****************.com United States*,***,***
*************.***.au United States*,***,***
See full domain list

FAQ

CVE-2026-59512 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Enquiry Quotation For Woocommerce
A total of 301 websites have been identified as vulnerable to CVE-2026-59512, based on global website indexing conducted by WebTechSurvey.
The Enquiry Quotation For Woocommerce is affected by the CVE-2026-59512 vulnerability.
Enquiry Quotation For Woocommerce versions up to and including 2.2.34.43 are vulnerable to CVE-2026-59512.