
🚨*CVE* CVE-2026-6725 The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode … https://www.cve.org/CVERecord?id=CVE-2026-6725 ----- Traducción: CVE-2026-6725 El … http://infoflow.cloud`
Post summary
This post announces a stored XSS flaw (CVE‑2026‑6725) in the WPC Smart Messages for WooCommerce plugin, giving technical details but no PoC, exploit, or patch information.

