Unauthorized Data Modification in Advanced Woo Labels for WooCommerce by WordPress
CVE-2026-12241

5.4MEDIUM

What is CVE-2026-12241?

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin allows for unauthorized modification of data due to an insecure capability check within the 'save_meta_boxes' function in all versions up to and including 2.51. This vulnerability enables authenticated attackers with Contributor access or higher to create AWS labels that do not undergo proper escaping, potentially compromising data integrity. Although a partial fix was implemented in version 2.46, users are advised to review their installation for any lingering vulnerabilities.

Affected Version(s)

Advanced Woo Labels – Product Labels & Badges for WooCommerce 0 <= 2.51

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio (Os)
.