Missing Authorization Vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce
CVE-2026-57390
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 July 2026
What is CVE-2026-57390?
The Extra Product Options Builder for WooCommerce by EDGARROJAS is susceptible to a missing authorization vulnerability. This issue arises from incorrectly configured access control security levels, allowing unauthorized actions by users in versions up to 1.2.167. If exploited, this vulnerability could lead to unauthorized access to sensitive functionalities within the plugin, putting user data at risk.
Affected Version(s)
Extra Product Options Builder for WooCommerce 0 <= 1.2.167