Arbitrary File Download Vulnerability in WooCommerce Book Price Plugin by WordPress
CVE-2026-22334
7.5HIGH
What is CVE-2026-22334?
The WooCommerce Book Price Plugin for WordPress is susceptible to an arbitrary file download vulnerability, specifically impacting versions 1.3 and earlier. This security flaw allows unauthorized users to download sensitive files from the server, potentially exposing critical information. Plugin maintainers and users are urged to update to secure versions to mitigate this risk and enhance overall security compliance.
Affected Version(s)
Woocommerce Book Price <= 1.3