CVE · Medium

CVE-2026-6447 — Call for Price for WooCommerce [woocommerce-call-for-price] < 4.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6447 Call for Price for WooCommerce [woocommerce-call-for-price] < 4.3.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 4.3.0 4.3.0 2026-05-01

CVE-2026-6447

A Stored Cross-Site Scripting vulnerability exists within the Call for Price for WooCommerce plugin on WordPress, affecting versions up to 4.2.0. The issue stems from inadequate handling of user input in admin settings, allowing malicious actors with elevated permissions to embed executable code into pages that will run when accessed by other users. This weakness specifically impacts multi-site configurations and installations where unfiltered HTML is restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.