PT-2026-35659 · WordPress · Wpc Smart Messages For Woocommerce
Djaidja Moundjid
·
Published
2026-04-28
·
Updated
2026-04-29
·
CVE-2026-6725
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPC Smart Messages for WooCommerce versions prior to 4.2.9
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts through the
text attribute of the wpcsm text rotator shortcode. These scripts execute whenever a user visits the affected page.Recommendations
Update to a version later than 4.2.8.
As a temporary workaround, restrict the use of the
text attribute within the wpcsm text rotator shortcode to trusted users only.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpc Smart Messages For Woocommerce