Description
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch or Disable
AI Analysis

Impact

The WPC Smart Compare for WooCommerce WordPress plugin before version 6.6.1 fails to enforce WordPress’s post‑password protection when serving product content through its comparison endpoint. This omission allows unauthenticated users to read the full description of password‑protected products, exposing data that should remain confidential. The flaw is a failure of access control, classified as CWE‑200, and can lead to disclosure of sensitive product information.

Affected Systems

The flaw impacts the WPC Smart Compare for WooCommerce WordPress plugin on all versions earlier than 6.6.1. No additional vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity, while the EPSS of less than 1% indicates a very low probability of exploitation. The vulnerability is not included in the CISA KEV catalog, suggesting no known widespread exploitation. An attacker could trigger the disclosure simply by sending a request to the plugin’s woosc_load endpoint as an unauthenticated user; no special privileges or prior compromise are required.

Generated by OpenCVE AI on September 23, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPC Smart Compare for WooCommerce plugin to version 6.6.1 or later, which restores the missing password protection check.
  • If an immediate upgrade is not feasible, configure your web server or a security plugin to block or require authentication for unauthenticated access to the woosc_load endpoint.
  • As a short‑term safeguard, consider disabling the compare feature or the plugin entirely on sites that use password‑protected products until the patch is applied.

Generated by OpenCVE AI on September 23, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
Title WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_load
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:52:43.052Z

Reserved: 2026-09-14T13:50:21.150Z

Link: CVE-2026-90985

cve-icon Vulnrichment

Updated: 2026-09-23T10:33:43.687Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:05.317

Modified: 2026-09-23T11:17:17.047

Link: CVE-2026-90985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor