PT-2025-42702 · WordPress · Wpc Smart Quick View For Woocommerce
Lucas Montes
·
Publicado
2025-10-18
·
Atualizado
2025-10-22
·
CVE-2025-11741
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WPC Smart Quick View for WooCommerce plugin versions through 4.2.5
Description
The WPC Smart Quick View for WooCommerce plugin for WordPress has an information exposure issue. Insufficient restrictions on posts included via the
woosq quickview API endpoint allows unauthenticated attackers to extract data from password-protected, private, or draft products that they should not have access to.Recommendations
Update the WPC Smart Quick View for WooCommerce plugin to a version later than 4.2.5.
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpc Smart Quick View For Woocommerce