Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder
CVE-2026-57664
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 June 2026
What is CVE-2026-57664?
The Bopo – WooCommerce Product Bundle Builder plugin for WordPress is vulnerable to unauthorized access, allowing attackers to potentially expose sensitive data without requiring authentication. This issue affects versions up to and including 1.1.6, and can lead to significant privacy concerns if exploited. Website administrators should review the plugin's current version and take immediate actions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Bopo – WooCommerce Product Bundle Builder <= 1.1.6