Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #6
WPC Product Options plugin hit by stored XSS flaw
Original: π¨ EUVD-2026-91952 π Score: 7.2/10 (CVSS v3.1) π¦ Product: WPC Product Options for WooCommerce π’ Vendor: WPClever π Update
A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.
Why now: WordPress store owners and security teams track new plugin vulnerabilities that could let attackers inject persistent scripts into e-commerce sites.
WPC Product Options for WooCommerceWPCleverWordPressWooCommerce
Rank over time, top of the chart is #1. 2 snapshots from 14 h ago to 14 h ago.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/835687