WordPress · Product Specifications For Woocommerce · CVE-2026-11364
**Name of the Vulnerable Software and Affected Versions**
Product Specifications for WooCommerce versions prior to 0.9.0
**Description**
Authenticated users with Subscriber-level access and above can perform unauthorized modification, creation, and deletion of product specification groups and attributes. This occurs because the ` invoke()` methods within the `AttributeGroupController` and `AttributeController` classes lack capability checks and nonce verification. These methods are linked to the 'dwps modify groups' and 'dwps modify attributes' AJAX actions. Exploitation allows attackers to manipulate taxonomy terms in the `spec-group` and attribute taxonomies, which can corrupt business data and affect the frontend display of the site.
**Recommendations**
Update Product Specifications for WooCommerce to a version newer than 0.8.9.