SecAlerts
w

wpclever

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 28, 2022 to present

20
Total CVEs
11
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
36/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
11
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
CSRF
2
3
Infoleak
1
4
Path Traversal
1
5
Code Injection
1

Most Affected Products

1. WPClever WPC Product Bundles for WooCommerce3
2. WPClever Wpc Smart Wishlist For Woocommerce Wordpress3
3. WPClever WPC Product Options for WooCommerce2
4. WPClever WPC Admin Columns1
5. WPClever WPC Smart Messages for WooCommerce1

Recent Vulnerabilities

See more →
CVE-2026-93836
CVSS 7.2EPSS 0%high

WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter

Sep 22, 2026🔧 No Patch
CVE-2026-18943
CVSS 6.5medium

WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure

Aug 12, 2026🔧 No Patch
CVE-2026-49061
CVSS 7.5high

WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-48883
CVSS 7.5high

WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access Control vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-6725
CVSS 6.4EPSS 0%medium

WPC Smart Messages for WooCommerce <= 4.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute

Apr 28, 2026🔧 No Patch
CVE-2026-32406
CVSS 4.3EPSS 0%medium

WordPress WPC Product Bundles for WooCommerce plugin <= 8.4.5 - Broken Access Control vulnerability

Mar 13, 2026🔧 No Patch
CVE-2025-60248
CVSS 7.5high

WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerability

Nov 6, 2025🔧 No Patch
CVE-2025-49908
CVSS 6.5medium

WordPress WPC Countdown Timer for WooCommerce plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability

Oct 22, 2025🔧 No Patch
CVE-2025-5530
CVSS 6.4medium

WPC Smart Compare for WooCommerce <= 6.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 11, 2025
CVE-2025-30825
CVSS 8.8EPSS 0%high

WordPress WPC Smart Linked Products plugin <= 1.3.5 - Privilege Escalation vulnerability

Apr 1, 2025

Monitor wpclever in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

wpclever Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts