WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.2.6
unknown
[en] The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract da...
- Affected:
- up to 4.2.6
- Fixed in:
- 4.2.6
- Disclosed:
- Oct 18, 2025
CVE-2025-11741 on NVD →
WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure
medium
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data fr...
- CVSS:
- 5.3
- Affected:
- up to 4.2.5
- Fixed in:
- 4.2.6
- Disclosed:
- Oct 17, 2025
CVE-2025-11741 on NVD →
WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode
medium
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Aug 19, 2025
CVE-2025-8618 on NVD →
WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.1.2
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.0.3
unknown
[en] The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Apr 13, 2024
CVE-2023-6494 on NVD →
WPC Smart Quick View for WooCommerce <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...
- CVSS:
- 4.4
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.3
- Disclosed:
- Apr 12, 2024
CVE-2023-6494 on NVD →
WPC Smart Quick View for WooCommerce [woo-smart-quick-view] < 4.2.2
unknown
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
CVE-2025-8618 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database