MikeTrendsTrends right now

search

WooCommerce

Trends

  1. 1
    WPC Product Options plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91952 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPC Product Options for WooCommerce ๐Ÿข Vendor: WPClever ๐Ÿ“… UpdateMmastodonTechnologyCybersecurity01 d ago

    A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

  2. 2
    Avada WordPress theme hit by reflected XSS vulnerabilityโ—๐Ÿšจ EUVD-2026-91174 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Avada | Website Builder For WordPress & WooCommerce ๐Ÿข Vendor: TMmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91174 with a CVSS score of 6.1, has been reported in Avada, the popular website builder theme for WordPress and WooCommerce from vendor ThemeFusion. The flaw is a reflected cross-site scripting issue, updated on 2026-10-02, allowing attackers to inject malicious scripts via crafted links. WordPress site owners using Avada are advised to update promptly.