PT-2026-53048 · WordPress · Product Specifications For Woocommerce
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Product Specifications for WooCommerce versions prior to 0.9.0
Description
Authenticated users with Subscriber-level access and above can perform unauthorized modification, creation, and deletion of product specification groups and attributes. This occurs because the
invoke() methods within the AttributeGroupController and AttributeController classes lack capability checks and nonce verification. These methods are linked to the 'dwps modify groups' and 'dwps modify attributes' AJAX actions. Exploitation allows attackers to manipulate taxonomy terms in the spec-group and attribute taxonomies, which can corrupt business data and affect the frontend display of the site.Recommendations
Update Product Specifications for WooCommerce to a version newer than 0.8.9.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Product Specifications For Woocommerce