Cross-Site Request Forgery in WooBeWoo Product Pricing Table Plugin for WordPress
CVE-2026-1852
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2026
What is CVE-2026-1852?
The Product Pricing Table plugin by WooBeWoo for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks due to inadequate nonce validation in its updateLabel() and remove() functions. This vulnerability allows unauthorized attackers to execute actions such as injecting arbitrary scripts into WordPress pages or removing pricing tables by tricking an authenticated site administrator into unknowingly executing a malicious request. This poses a significant threat to the integrity and functionality of WordPress sites utilizing this plugin.
Affected Version(s)
Product Pricing Table by WooBeWoo 0 <= 1.1.0