MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 9 h ago, last 9 h ago, peak #6

WPC Product Options plugin hit by stored XSS flaw

Original: 🚨 EUVD-2026-91952 πŸ“Š Score: 7.2/10 (CVSS v3.1) πŸ“¦ Product: WPC Product Options for WooCommerce 🏒 Vendor: WPClever πŸ“… Update

A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

Why now: WordPress store owners and security teams track new plugin vulnerabilities that could let attackers inject persistent scripts into e-commerce sites.

WPC Product Options for WooCommerceWPCleverWordPressWooCommerce

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/835687