search
WooCommerce
Trends
- 1WPC Product Options plugin hit by stored XSS flawโผ๐จ EUVD-2026-91952 ๐ Score: 7.2/10 (CVSS v3.1) ๐ฆ Product: WPC Product Options for WooCommerce ๐ข Vendor: WPClever ๐ Update
A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.