CVE-2026-90985: WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_load
Published Sep 23, 2026
·Updated
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
Affected Software
1 affected component
WPClever WPC Smart Compare for WooCommerce<6.6.1
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which installations are affected?
Installations using WPC Smart Compare for WooCommerce versions earlier than 6.6.1 are affected.
2
Does exploitation require authentication?
No. An unauthenticated user can exploit the comparison handler to retrieve protected product content.
3
What information can be exposed?
The description of a password-protected product can be disclosed because the handler does not enforce WordPress post-password protection.