CVE-2025-7496: WPC Smart Compare for WooCommerce <= 6.4.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, 6.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7496?
CVE-2025-7496 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-7496?
To fix CVE-2025-7496, update the WPC Smart Compare for WooCommerce plugin to version 6.4.8 or later, which addresses the vulnerability.
Who is affected by CVE-2025-7496?
CVE-2025-7496 affects all versions of the WPC Smart Compare for WooCommerce plugin up to and including 6.4.7.
What does CVE-2025-7496 exploit?
CVE-2025-7496 exploits insufficient input sanitization and output escaping, allowing stored cross-site scripting for authenticated users.
What should I do if I can't update from CVE-2025-7496?
If you cannot update to fix CVE-2025-7496, consider disabling the plugin or implementing custom security measures to mitigate risk.