Improper Input Validation in Advanced Product Fields for WooCommerce Plugin by WordPress
CVE-2026-2996
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-2996?
The Advanced Product Fields for WooCommerce plugin for WordPress suffers from an improper input validation flaw in the 'validate_cart_data' function. This vulnerability allows unauthenticated attackers to circumvent required paid add-ons, completing purchases at the base product price only. Consequently, attackers can exploit this flaw to acquire products for significantly less than intended. A partial patch was released in version 1.6.19, but all versions up to and including 1.6.21 remain vulnerable.
Affected Version(s)
Advanced Product Fields (Product Addons) for WooCommerce 0 <= 1.6.21