Stored Cross-Site Scripting in WPC Smart Compare for WooCommerce Plugin
CVE-2025-5530
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 July 2025
What is CVE-2025-5530?
The WPC Smart Compare for WooCommerce plugin allows authenticated users with contributor-level access or higher to exploit a vulnerability related to stored cross-site scripting. This occurs through insufficient input sanitization and output escaping of user-supplied attributes in the plugin's 'shortcode_btn' shortcode, enabling attackers to inject arbitrary web scripts. These scripts can be executed on pages whenever they are accessed by users, posing significant security risks.
Affected Version(s)
WPC Smart Compare for WooCommerce * <= 6.4.6