Access Control Security Flaw in ProWCPlugins Product Price for WooCommerce
CVE-2026-39662

5.3MEDIUM

What is CVE-2026-39662?

A flaw exists in the ProWCPlugins Product Price by Formula for WooCommerce plugin, which allows attackers to exploit incorrectly configured access control security levels. This vulnerability can lead to unauthorized access and manipulation of product pricing information, affecting any installations of the plugin from unspecified versions up to and including 2.5.6. Awareness of this vulnerability is critical for maintaining the security and integrity of WooCommerce-based online stores.

Affected Version(s)

Product Price by Formula for WooCommerce 0 <= 2.5.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.