Medium 5.3
2025-10-18< 4.2.6
CVE-2025-11741
Minimum safe version
4.2.6
Update to 4.2.6 or later to address 4 fixable vulnerabilities
CVE-2025-11741
WPC Smart Quick View for WooCommerce <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
WordPress WPC Smart Quick View for WooCommerce Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)