Unauthorized Data Modification in Advanced Woo Labels for WooCommerce by WordPress
CVE-2026-12241
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-12241?
The Advanced Woo Labels β Product Labels & Badges for WooCommerce plugin allows for unauthorized modification of data due to an insecure capability check within the 'save_meta_boxes' function in all versions up to and including 2.51. This vulnerability enables authenticated attackers with Contributor access or higher to create AWS labels that do not undergo proper escaping, potentially compromising data integrity. Although a partial fix was implemented in version 2.46, users are advised to review their installation for any lingering vulnerabilities.
Affected Version(s)
Advanced Woo Labels β Product Labels & Badges for WooCommerce 0 <= 2.51