Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce
CVE-2026-48883
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-48883?
The WPC Product Bundles for WooCommerce plugin versions up to 8.5.3 suffer from an unauthenticated broken access control vulnerability. This flaw allows unauthorized users to interact with restricted areas of the application, potentially leading to unauthorized access and data manipulation. As such, it is crucial for users of this plugin to ensure they are running the latest version to mitigate any risks associated with this vulnerability.
Affected Version(s)
WPC Product Bundles for WooCommerce <= 8.5.3