Cross-Site Request Forgery in WooBeWoo Product Pricing Table Plugin for WordPress
CVE-2026-1852

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-1852?

The Product Pricing Table plugin by WooBeWoo for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks due to inadequate nonce validation in its updateLabel() and remove() functions. This vulnerability allows unauthorized attackers to execute actions such as injecting arbitrary scripts into WordPress pages or removing pricing tables by tricking an authenticated site administrator into unknowingly executing a malicious request. This poses a significant threat to the integrity and functionality of WordPress sites utilizing this plugin.

Affected Version(s)

Product Pricing Table by WooBeWoo 0 <= 1.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Nur Ibnu Hubab
.