AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16620

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WPC Name Your Price for WooCommerce plugin prior to version 2.2.5 is vulnerable due to a failure to enforce server-side price restrictions for products in "Select" price mode, allowing unauthenticated users to manipulate product prices and place orders at significantly lower values than intended. This flaw can lead to substantial revenue loss for merchants as it permits underpriced orders to be processed. E-commerce businesses using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16620
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.