Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce
CVE-2026-48883

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-48883?

The WPC Product Bundles for WooCommerce plugin versions up to 8.5.3 suffer from an unauthenticated broken access control vulnerability. This flaw allows unauthorized users to interact with restricted areas of the application, potentially leading to unauthorized access and data manipulation. As such, it is crucial for users of this plugin to ensure they are running the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

WPC Product Bundles for WooCommerce <= 8.5.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.