---
id: CVE-2025-11741
title: >-
  The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to
  Information Exposure in all versions up to, and including, 4.2.5 via the
  'woosq_quickview' AJAX endpoint due to insufficient restrictions on which
  posts can b…
summary: >-
  The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to
  Information Exposure in all versions up to, and including, 4.2.5 via the
  'woosq_quickview' AJAX endpoint due to insufficient restrictions on which
  posts can b…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
published: '2025-10-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11741'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3379189%40woo-smart-quick-view&new=3379189%40woo-smart-quick-view&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/220487de-2a1c-47ec-ac65-db1af44aed3d?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00336
epssPercentile: 0.24915
ingestedAt: '2026-10-08T22:11:53.809Z'
---

## Overview

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft products that they should not have access to.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
