SecAlerts
wpc logo

wpc

Security Risk Profile

33
/100
low

Security Risk Score

Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 13, 2024 to present

15
Total CVEs
4
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
33/100
low

Severity Distribution

Critical
0
High
4
Medium
11
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
CSRF
1
3
Code Injection
1

Most Affected Products

1. WPC Smart Quick View for WooCommerce3
2. WPC Smart Wishlist for WooCommerce2
3. WPC Smart Compare for WooCommerce2
4. WPC Smart Messages for WooCommerce2
5. WPC WPC Badge Management for WooCommerce1

Recent Vulnerabilities

See more →
CVE-2025-14767
CVSS 5.5medium

WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute

5/13/2026🔧 No Patch
CVE-2025-12115
CVSS 7.5high

WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration

10/31/2025🔧 No Patch
CVE-2025-11741
CVSS 5.3medium

WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure

10/18/2025🔧 No Patch
CVE-2025-11742
CVSS 4.3medium

WPC Smart Wishlist for WooCommerce <= 5.0.4 - Missing Authorization to Authenticated (Subscriber+) Information Exposure

10/18/2025🔧 No Patch
CVE-2025-11518
CVSS 5.3medium

WPC Smart Wishlist for WooCommerce <= 5.0.3 - Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation

10/11/2025🔧 No Patch
CVE-2025-8618
CVSS 6.4EPSS 0%medium

WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode

8/20/2025🔧 No Patch
CVE-2025-7496
CVSS 6.4medium

WPC Smart Compare for WooCommerce <= 6.4.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

8/19/2025🔧 No Patch
CVE-2025-5530
CVSS 6.4medium

WPC Smart Compare for WooCommerce <= 6.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

7/11/2025
CVE-2025-3418
CVSS 8.8EPSS 0%high

WPC Admin Columns 2.0.6 - 2.1.0 - Authenticated (Subscriber+) Privilege Escalation via User Meta Update

4/12/2025🔧 No Patch
CVE-2024-12432
CVSS 8.1high

WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key

12/18/2024🔧 No Patch

Monitor wpc in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpc Security Vulnerabilities & Risk Score | 15 CVEs | SecAlerts - SecAlerts