vciy

CVEs we hold for Wpclever

Records whose assigning authority named Wpclever as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7436WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text'…wpclever WPC Badge Management for WooCommerce
CVE-2026-6725WPC Smart Messages for WooCommerce <= 4.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…wpclever WPC Smart Messages for WooCommerce
CVE-2026-49061WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerabilityWPClever WPC Product Options for WooCommerce
CVE-2026-48883WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access Control vulnerabilityWPClever WPC Product Bundles for WooCommerce
CVE-2026-32407WordPress WPC Smart Wishlist for WooCommerce plugin <= 5.0.8 - Broken Access Control vulnerabilityWPClever WPC Smart Wishlist for WooCommerce
CVE-2026-32406WordPress WPC Product Bundles for WooCommerce plugin <= 8.4.5 - Broken Access Control vulnerabilityWPClever WPC Product Bundles for WooCommerce
CVE-2025-8618WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn…wpclever WPC Smart Quick View for WooCommerce
CVE-2025-7496WPC Smart Compare for WooCommerce <= 6.4.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingwpclever WPC Smart Compare for WooCommerce
CVE-2025-62903WordPress WPC Smart Messages for WooCommerce plugin <= 4.2.8 - Cross Site Scripting (XSS) vulnerabilityWPClever WPC Smart Messages for WooCommerce
CVE-2025-60248WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerabilityWPClever WPC Product Options for WooCommerce
CVE-2025-5530WPC Smart Compare for WooCommerce <= 6.4.6 - Authenticated (Contributor+) Stored Cross-Site Scriptingwpclever WPC Smart Compare for WooCommerce
CVE-2025-49908WordPress WPC Countdown Timer for WooCommerce plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerabilityWPClever WPC Countdown Timer for WooCommerce
CVE-2025-3418WPC Admin Columns 2.0.6 - 2.1.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta Updatewpclever WPC Admin Columns
CVE-2025-30825WordPress WPC Smart Linked Products plugin <= 1.3.5 - Privilege Escalation vulnerabilityWPClever WPC Smart Linked Products - Upsells & Cross-sells…
CVE-2025-30772WordPress WPC Smart Upsell Funnel for WooCommerce plugin <= 3.0.4 - Arbitrary Option Update to Privilege Escalation…WPClever WPC Smart Upsell Funnel for WooCommerce
CVE-2025-14767WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text'…wpclever WPC Badge Management for WooCommerce
CVE-2025-12115WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alterationwpclever WPC Name Your Price for WooCommerce
CVE-2025-11742WPC Smart Wishlist for WooCommerce <= 5.0.4 - Missing Authorization to Authenticated (Subscriber+) Information Exposurewpclever WPC Smart Wishlist for WooCommerce
CVE-2025-11741WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product…wpclever WPC Smart Quick View for WooCommerce
CVE-2025-11518WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulationwpclever WPC Smart Wishlist for WooCommerce
CVE-2024-50416WordPress WPC Shop as a Customer for WooCommerce plugin <= 1.2.6 - PHP Object Injection vulnerabilityWPClever WPC Shop as a Customer for WooCommerce
CVE-2024-43312WordPress WPC Frequently Bought Together for WooCommerce plugin <= 7.1.9 - Broken Access Control vulnerabilityWPClever WPC Frequently Bought Together for WooCommerce
CVE-2024-32687WordPress WPC Frequently Bought Together for WooCommerce plugin <= 7.0.3 - Broken Access Control vulnerabilityWPClever WPC Frequently Bought Together for WooCommerce
CVE-2024-32520WordPress WPC Grouped Product for WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerabilityWPClever WPC Grouped Product for WooCommerce
CVE-2024-30537WordPress WPC Badge Management for WooCommerce plugin <= 2.4.0 - Broken Access Control vulnerabilityWPClever WPC Badge Management for WooCommerce
CVE-2024-2838WPC Composite Products for WooCommerce <= 7.2.7 - Authenticated (Subscriber+) Stored Cross-Site Scriptingwpclever WPC Composite Products for WooCommerce
CVE-2024-12432WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Keywpclever WPC Shop as a Customer for WooCommerce
CVE-2024-12004WPC Order Notes for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Reflected Cross-Site Scriptingwpclever WPC Order Notes for WooCommerce
CVE-2024-10437WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message…wpclever WPC Smart Messages for WooCommerce
CVE-2024-10436WPC Smart Messages for WooCommerce <= 4.2.1 - Authenticated (Subscriber+) Local File Inclusionwpclever WPC Smart Messages for WooCommerce
CVE-2023-6494WPC Smart Quick View for WooCommerce <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scriptingwpclever WPC Smart Quick View for WooCommerce
CVE-2023-52127WordPress WPC Product Bundles for WooCommerce Plugin <= 7.3.1 is vulnerable to Cross Site Request Forgery (CSRF)WPClever WPC Product Bundles for WooCommerce
CVE-2023-34386WordPress WPC Smart Wishlist for WooCommerce Plugin <= 4.7.1 is vulnerable to Cross Site Request Forgery (CSRF)WPClever WPC Smart Wishlist for WooCommerce

33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.