plugin

Woo Smart Quick View Vulnerabilities

8 known security issues reported for the Woo Smart Quick View WordPress plugin. Most recent disclosed Oct 18, 2025.

4 medium

Running Woo Smart Quick View on your site? Check whether your installed version is affected.

Scan your site free

WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.2.6

unknown

[en] The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract da...

Affected:
up to 4.2.6
Fixed in:
4.2.6
Disclosed:
Oct 18, 2025

CVE-2025-11741 on NVD →

WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure

medium

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data fr...

CVSS:
5.3
Affected:
up to 4.2.5
Fixed in:
4.2.6
Disclosed:
Oct 17, 2025

CVE-2025-11741 on NVD →

WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode

medium

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Aug 19, 2025

CVE-2025-8618 on NVD →

WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.1.2

unknown

[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...

Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Dec 4, 2024

CVE-2024-5020 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Dec 3, 2024

CVE-2024-5020 on NVD →

WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.0.3

unknown

[en] The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Apr 13, 2024

CVE-2023-6494 on NVD →

WPC Smart Quick View for WooCommerce <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

CVSS:
4.4
Affected:
up to 4.0.2
Fixed in:
4.0.3
Disclosed:
Apr 12, 2024

CVE-2023-6494 on NVD →

WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.2.2

unknown
Affected:
up to 4.2.2
Fixed in:
4.2.2

CVE-2025-8618 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database