Improper Input Validation in Advanced Product Fields for WooCommerce Plugin by WordPress
CVE-2026-2996

7.5HIGH

What is CVE-2026-2996?

The Advanced Product Fields for WooCommerce plugin for WordPress suffers from an improper input validation flaw in the 'validate_cart_data' function. This vulnerability allows unauthenticated attackers to circumvent required paid add-ons, completing purchases at the base product price only. Consequently, attackers can exploit this flaw to acquire products for significantly less than intended. A partial patch was released in version 1.6.19, but all versions up to and including 1.6.21 remain vulnerable.

Affected Version(s)

Advanced Product Fields (Product Addons) for WooCommerce 0 <= 1.6.21

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrés Cruciani
.