Wpclever develops a focused line of WordPress e-commerce plugins for WooCommerce, including product management, bundling, and customer-experience extensions that integrate with store catalogs and checkout workflows. The vendor's vulnerability profile centers on application-layer input handling and access-control weaknesses such as cross-site scripting, CSRF, missing authorization, and code-injection flaws that are characteristic of plugins operating in shared WordPress environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpclever over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48883HIGH Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-50416HIGH Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Cus | Oct 28, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-30537HIGH Missing Authorization vulnerability in WPClever WPC Badge Management for WooCommerce.This issue affects WPC Badge Management for WooCommerce: from n/a through 2.4.0. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-52127HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Product Bundles for WooCommerce.This issue affects WPC Product Bundles for WooCommerce: from n/a through 7.3.1. | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-34386HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions. | Nov 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-14767MEDIUM The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all vers | May 13, 2026 | 5.5 | 23 | NO | NO |
CVE-2024-12432HIGH The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due | Dec 18, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-43312HIGH Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-7496MEDIUM The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, 6.4.7 due to insuffic | Aug 19, 2025 | 6.4 | 22 | NO | NO |
CVE-2022-1465MEDIUM The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading | May 16, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpclever.
Media articles that mention a CVE ID that affects a product developed by Wpclever — matched by CVE ID, not by vendor name.