PT-2026-97198 · WordPress · Wc Fields Factory

·

CVE-2026-93508

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WC Fields Factory WordPress plugin versions prior to 4.1.11
Description Insufficient access restrictions on the field-management AJAX action allow authenticated users with Subscriber-level permissions or higher to create, modify, and delete arbitrary post meta on any post. This includes WooCommerce products, regardless of who owns them. An attacker can use this to manipulate stored pricing rules on a product to lower its price during checkout.
Recommendations Update WC Fields Factory WordPress plugin to version 4.1.11 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93508

Affected Products

Wc Fields Factory