Unauthorized Price Alteration in WooCommerce Plugin by WPC
CVE-2025-12115

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 October 2025

What is CVE-2025-12115?

The WPC Name Your Price for WooCommerce plugin for WordPress has a significant vulnerability that allows unauthenticated users to manipulate the price of products. This flaw persists in all versions up to and including 2.1.9. The plugin fails to properly enforce restrictions on custom pricing options, even when they are disabled for specific products. As a result, attackers can exploit this weakness to acquire products at artificially low prices, undermining both the integrity of the sale and the revenue of the store.

Affected Version(s)

WPC Name Your Price for WooCommerce * <= 2.1.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-12115 : Unauthorized Price Alteration in WooCommerce Plugin by WPC