PT-2026-79550 · WordPress · Advanced Product Fields
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced Product Fields (Product Addons) for WooCommerce versions prior to 1.6.22
Description
Improper Input Validation occurs due to a logic flaw in the
validate cart data() function. This allows unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, resulting in the acquisition of products for a fraction of the intended total.Recommendations
Update Advanced Product Fields (Product Addons) for WooCommerce to version 1.6.22 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Product Fields