CVE-2026-61945

WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.


We have discovered 407 live websites that are affected by CVE-2026-61945.

Run a Free Instant Scan




Affected Software

Product  Woocommerce Product Stock Alert
Category Wordpress Plugins
Vulnerable Domains407 live websites (100% of Woocommerce Product Stock Alert install base)
Vulnerable Versions
  • from 0 through 3.0.6
Vulnerable Versions Count31 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Jakub Herman | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-61945
United States77 websites



Spain54 websites
France42 websites
Germany30 websites
Poland23 websites
Italy19 websites
GB12 websites
Australia11 websites
Romania10 websites
Russia9 websites

Website Distribution by TLD

Number of websites using CVE-2026-61945
.com178 websites
.es19 websites
.fr16 websites
.it16 websites
.pl14 websites
.com.au12 websites
.de12 websites
.eu9 websites
.nl7 websites
.ru7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-61945

Top websites that are affected by CVE-2026-61945. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.com United States***,***
******.es Spain***,***
*********************.org GB***,***
**************.com United States*,***,***
****.com Netherlands*,***,***
**********.fr France*,***,***
**************.nl Netherlands*,***,***
********.fi Germany*,***,***
********.org Germany*,***,***
********.pl Poland*,***,***
See full domain list

FAQ

CVE-2026-61945 is Exposure of Sensitive System Information to an Unauthorized Control Sphere in Woocommerce Product Stock Alert
A total of 407 websites have been identified as vulnerable to CVE-2026-61945, based on global website indexing conducted by WebTechSurvey.
The Woocommerce Product Stock Alert is affected by the CVE-2026-61945 vulnerability.
Woocommerce Product Stock Alert versions up to and including 3.0.6 are vulnerable to CVE-2026-61945.