Impact
The WPC Smart Compare for WooCommerce WordPress plugin before version 6.6.1 fails to enforce WordPress’s post‑password protection when serving product content through its comparison endpoint. This omission allows unauthenticated users to read the full description of password‑protected products, exposing data that should remain confidential. The flaw is a failure of access control, classified as CWE‑200, and can lead to disclosure of sensitive product information.
Affected Systems
The flaw impacts the WPC Smart Compare for WooCommerce WordPress plugin on all versions earlier than 6.6.1. No additional vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS of less than 1% indicates a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, suggesting no known widespread exploitation. An attacker could trigger the disclosure simply by sending a request to the plugin’s woosc_load endpoint as an unauthenticated user; no special privileges or prior compromise are required.
OpenCVE Enrichment