CyberRota Analysis
AI-GeneratedThe Advanced Product Fields (Product Addons) for WooCommerce plugin in WordPress is vulnerable due to improper input validation, allowing unauthenticated attackers to exploit a logic flaw in the 'validate_cart_data' function. This enables them to bypass payment for required addons, resulting in unauthorized purchases at significantly reduced prices. WordPress site administrators using this plugin should prioritize applying the latest updates to mitigate the risk of financial loss and product theft.
Original NVD Description
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.