SecAlerts
wpclever logo

wpclever

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 28, 2022 to present

19
Total CVEs
10
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
43/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
10
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
CSRF
2
3
Infoleak
1
4
Path Traversal
1
5
Code Injection
1

Most Affected Products

1. WPClever Wpc Smart Wishlist For Woocommerce Wordpress3
2. WPClever WPC Product Options for WooCommerce2
3. WPClever WPC Product Bundles for WooCommerce2
4. WPClever WPC Admin Columns1
5. WPClever WPC Smart Messages for WooCommerce1

Recent Vulnerabilities

See more →
CVE-2026-18943
unknown

WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure

8/12/2026🔧 No Patch
CVE-2026-49061
CVSS 7.5high

WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability

6/15/2026🔧 No Patch
CVE-2026-48883
CVSS 7.5high

WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access Control vulnerability

6/15/2026🔧 No Patch
CVE-2026-6725
CVSS 6.4EPSS 0%medium

WPC Smart Messages for WooCommerce <= 4.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute

4/28/2026🔧 No Patch
CVE-2026-32406
CVSS 4.3EPSS 0%medium

WordPress WPC Product Bundles for WooCommerce plugin <= 8.4.5 - Broken Access Control vulnerability

3/13/2026🔧 No Patch
CVE-2025-60248
CVSS 7.5high

WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerability

11/6/2025🔧 No Patch
CVE-2025-49908
CVSS 6.5medium

WordPress WPC Countdown Timer for WooCommerce plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability

10/22/2025🔧 No Patch
CVE-2025-5530
CVSS 6.4medium

WPC Smart Compare for WooCommerce <= 6.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

7/11/2025
CVE-2025-30825
CVSS 8.8EPSS 0%high

WordPress WPC Smart Linked Products plugin <= 1.3.5 - Privilege Escalation vulnerability

4/1/2025
CVE-2025-30772
CVSS 8.8EPSS 0%high

WordPress WPC Smart Upsell Funnel for WooCommerce plugin <= 3.0.4 - Arbitrary Option Update to Privilege Escalation vulnerability

3/27/2025🔧 No Patch

Monitor wpclever in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpclever Security Vulnerabilities & Risk Score | 19 CVEs | SecAlerts - SecAlerts