CVE-2026-90985
Received Received - Intake

Unauthenticated Access to Password-Protected Products in WPC Smart Compare for WooCommerce

Vulnerability report for CVE-2026-90985, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wpc simple_compare to 6.6.1 (exc)
wpc sma rt_compare_for_woocommerce to 6.6.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WPC Smart Compare for WooCommerce WordPress plugin before version 6.6.1. It allows unauthenticated users to read the descriptions of password-protected products because the plugin does not enforce WordPress's post-password protection when returning product content through its comparison handler.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the 'WPC Smart Compare for WooCommerce' plugin version prior to 6.6.1. You can verify the plugin version via the WordPress admin panel under Plugins. Additionally, test if unauthenticated users can access password-protected product descriptions through the plugin's comparison handler by attempting to view such products without authentication.

Impact Analysis

Unauthenticated users could access sensitive product descriptions that were intended to be restricted. This may lead to unauthorized disclosure of confidential or proprietary information, affecting business confidentiality and customer trust.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations using the affected plugin may face compliance violations and legal consequences.

Mitigation Strategies

Immediately update the 'WPC Smart Compare for WooCommerce' plugin to version 6.6.1 or later. If an update is not available, consider disabling the plugin temporarily until a patch is released. Review your site's access logs for suspicious requests to password-protected product endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90985. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart