PT-2026-53048 · WordPress · Product Specifications For Woocommerce

·

CVE-2026-11364

·

Published

2026-06-27

·

Updated

2026-06-27

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Product Specifications for WooCommerce versions prior to 0.9.0
Description Authenticated users with Subscriber-level access and above can perform unauthorized modification, creation, and deletion of product specification groups and attributes. This occurs because the invoke() methods within the AttributeGroupController and AttributeController classes lack capability checks and nonce verification. These methods are linked to the 'dwps modify groups' and 'dwps modify attributes' AJAX actions. Exploitation allows attackers to manipulate taxonomy terms in the spec-group and attribute taxonomies, which can corrupt business data and affect the frontend display of the site.
Recommendations Update Product Specifications for WooCommerce to a version newer than 0.8.9.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11364

Affected Products

Product Specifications For Woocommerce