WPC Smart Quick View for WooCommerce <= 4.4.1 - Unauthenticated Sensitive Information Exposure via Password-Protected Products in Quick View

Medium 5.3 CWE-200Fixed in 4.4.2
ID
WPSEC-2026-0459
Plugin
WPC Smart Quick View for WooCommerce (woo-smart-quick-view)
Affected
all versions before 4.4.2
Remediation
Update to 4.4.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
WPC Smart Quick View for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1. The 'woosq_quickview' WooCommerce AJAX endpoint renders a product's summary without checking whether the product is password-protected. This makes it possible for unauthenticated attackers to read the short description of password-protected products, and the full description where the quick view is configured to show it. WooCommerce otherwise shows this content only after the product password is entered.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0