Vulnerabilities / WPC Smart Quick View for WooCommerce / WPSEC-2026-0459
WPC Smart Quick View for WooCommerce <= 4.4.1 - Unauthenticated Sensitive Information Exposure via Password-Protected Products in Quick View
Medium 5.3
CWE-200Fixed in 4.4.2
- ID
- WPSEC-2026-0459
- Plugin
- WPC Smart Quick View for WooCommerce (woo-smart-quick-view)
- Affected
- all versions before 4.4.2
- Remediation
- Update to 4.4.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- WPC Smart Quick View for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1. The 'woosq_quickview' WooCommerce AJAX endpoint renders a product's summary without checking whether the product is password-protected. This makes it possible for unauthenticated attackers to read the short description of password-protected products, and the full description where the quick view is configured to show it. WooCommerce otherwise shows this content only after the product password is entered.
References
- https://wpsec.com/vuln/WPSEC-2026-0459/
- https://plugins.svn.wordpress.org/woo-smart-quick-view/tags/4.4.2/
- https://wordpress.org/plugins/woo-smart-quick-view/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS