CVE-2026-2996

7.5

maartenbelmans · Advanced Product Fields (Product Addons) for WooCommerce

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation, allowing unauthenticated attackers to modify product data.

Executive summary

An Improper Input Validation vulnerability in the Advanced Product Fields for WooCommerce plugin allows unauthenticated attackers to corrupt or modify product data.

Vulnerability

The plugin suffers from improper input validation (CWE-20), which can be leveraged by unauthenticated attackers to manipulate input parameters. This allows for unauthorized modification of product fields within the WooCommerce environment.

Business impact

While the CVSS score is 7.5, the impact is focused on the integrity of the e-commerce store. Successful exploitation could allow an attacker to alter pricing, product descriptions, or other critical fields, leading to financial loss or severe reputational damage to the business.

Remediation

Immediate Action: Update the Advanced Product Fields (Product Addons) for WooCommerce plugin to version 1.6.22 or later.

Proactive Monitoring: Monitor WooCommerce product modification logs for unauthorized changes or anomalies in product data entries.

Compensating Controls: Implement strict WAF rules to validate and sanitize incoming requests to the WooCommerce checkout and product management endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a direct risk to the integrity of store operations. It is essential to apply the provided patch to version 1.6.22 to ensure that input parameters are properly validated and to prevent unauthorized modification of store data.