Executive brief
WCBoost – Products Compare is a WordPress plugin that allows customers to compare different products on an e-commerce site. A security vulnerability in versions 1.1.0 and earlier allows unauthenticated visitors to access sensitive system information that should be restricted. This exposure could provide attackers with technical details useful for planning more advanced attacks against the website.
Technical details
The WCBoost – Products Compare plugin for WordPress is vulnerable to sensitive data exposure (CWE-497) in versions up to 1.1.0. The vulnerability allows an unauthenticated remote attacker to access sensitive system information due to improper restriction of the control sphere. This is a network-based attack that requires no user interaction or special privileges. Attackers can leverage this exposed information to gain insights into the system's configuration or environment, potentially facilitating further exploitation. The issue is resolved in version 1.1.1.
Affected products
- WCBoost WCBoost – Products Compare <= 1.1.0
Timeline
- 2026-06-04: other: Reported by researcher
- 2026-06-26: advisory: Patchstack advisory published
- 2026-06-26: disclosed: NVD publication date