CVE-2026-90985: CWE-200 Information Exposure in WPC Smart Compare for WooCommerce
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
AI Analysis
Technical Summary
The WPC Smart Compare for WooCommerce WordPress plugin prior to version 6.6.1 fails to apply WordPress's post-password protection mechanism when returning product content through its comparison handler. As a result, unauthenticated users can read the descriptions of products that are intended to be password-protected, leading to information exposure classified under CWE-200.
Potential Impact
Unauthenticated users can access product descriptions that should be restricted by password protection, potentially exposing sensitive or confidential product information.
Mitigation Recommendations
Upgrade the WPC Smart Compare for WooCommerce plugin to version 6.6.1 or later, where this issue is fixed. No other mitigation is necessary once the plugin is updated.
CVE-2026-90985: CWE-200 Information Exposure in WPC Smart Compare for WooCommerce
Description
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
CVSS v3.1
Score 5.3medium
Affected software
WPC Smart Compare for WooCommerce
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WPC Smart Compare for WooCommerce WordPress plugin prior to version 6.6.1 fails to apply WordPress's post-password protection mechanism when returning product content through its comparison handler. As a result, unauthenticated users can read the descriptions of products that are intended to be password-protected, leading to information exposure classified under CWE-200.
Potential Impact
Unauthenticated users can access product descriptions that should be restricted by password protection, potentially exposing sensitive or confidential product information.
Mitigation Recommendations
Upgrade the WPC Smart Compare for WooCommerce plugin to version 6.6.1 or later, where this issue is fixed. No other mitigation is necessary once the plugin is updated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-14T13:50:21.150Z
- State
- PUBLISHED
Threat ID: 6ab36d43f7a7c541065abccc
Added to database: 09/23/2026, 06:10:11 UTC
Last enriched: 09/23/2026, 06:18:13 UTC
Last updated: 09/24/2026, 01:57:05 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.