PT-2026-97198 · WordPress · Wc Fields Factory
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WC Fields Factory WordPress plugin versions prior to 4.1.11
Description
Insufficient access restrictions on the field-management AJAX action allow authenticated users with Subscriber-level permissions or higher to create, modify, and delete arbitrary post meta on any post. This includes WooCommerce products, regardless of who owns them. An attacker can use this to manipulate stored pricing rules on a product to lower its price during checkout.
Recommendations
Update WC Fields Factory WordPress plugin to version 4.1.11 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wc Fields Factory