WPC Smart Messages for WooCommerce
WPClever- Software type
- —
- Catalog vulnerabilities
- 4
Severity across 4 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 4 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 4 vulnerability records affecting WPC Smart Messages for WooCommerce.
Among the 4 records analyzed by CyStack, 1 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-6725WPC Smart Messages for WooCommerce <= 4.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityMedium |
CVE-2025-62903WordPress WPC Smart Messages for WooCommerce plugin <= 4.2.8 - Cross Site Scripting (XSS) vulnerability | Exploitation statusNot known exploited | FixYes | Published10/27/2025 | SeverityMedium |
CVE-2024-10437WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation | Exploitation statusNot known exploited | FixYes | Published10/29/2024 | SeverityMedium |
CVE-2024-10436WPC Smart Messages for WooCommerce <= 4.2.1 - Authenticated (Subscriber+) Local File Inclusion | Exploitation statusNot known exploited | FixYes | Published10/29/2024 | SeverityHigh |