SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-2996

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Advanced Product Fields (Product Addons) for WooCommerce plugin in WordPress is vulnerable due to improper input validation, allowing unauthenticated attackers to exploit a logic flaw in the 'validate_cart_data' function. This enables them to bypass payment for required addons, resulting in unauthorized purchases at significantly reduced prices. WordPress site administrators using this plugin should prioritize applying the latest updates to mitigate the risk of financial loss and product theft.

CVE
CVE-2026-2996
Severity
HIGH
CVSS
7.5
EPSS
0.49%
WordPress

Original NVD Description

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.