Missing Authorization Flaw in WPClever WPC Product Bundles for WooCommerce
CVE-2026-32406
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 March 2026
What is CVE-2026-32406?
A missing authorization vulnerability exists in WPClever's WPC Product Bundles for WooCommerce plugin, affecting versions up to 8.4.5. This flaw allows attackers to exploit improperly configured access control measures, potentially granting unauthorized access to sensitive functionalities and data within the application. It is crucial for users to apply the necessary updates or patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
WPC Product Bundles for WooCommerce 0 <= 8.4.5