Authorization Bypass in VillaTheme COMPE Plugin for WooCommerce
CVE-2026-40737

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
15 April 2026

What is CVE-2026-40737?

The VillaTheme COMPE WooCommerce Compare Products plugin is vulnerable to an authorization bypass due to incorrectly configured access control security levels. This allows malicious users to exploit the system by manipulating user-controlled keys, potentially gaining unauthorized access to sensitive functionality. The issue affects versions prior to 1.1.5, posing a significant risk to sites utilizing this plugin.

Affected Version(s)

COMPE 0 <= 1.1.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Osman ERBAS (0110m4n) | Patchstack Bug Bounty Program
.