Executive brief
A vulnerability in the Product Configurator for WooCommerce plugin for WordPress allows unauthorized individuals to view details of products that are not yet public. This includes sensitive information such as pricing, stock levels, and SKUs for items currently in draft or private status. An attacker could use this to gain competitive intelligence or see unreleased product details before an official launch.
Technical details
The Product Configurator for WooCommerce plugin (versions prior to 1.7.3) contains an information disclosure vulnerability due to missing authorization and post-status checks in its AJAX handling logic. Specifically, the 'pc_get_data' action allows unauthenticated remote attackers to query product details by providing a product ID. Because the plugin does not verify if the requested product is published or if the user has permission to view it, it returns sensitive data—including titles, prices, weights, stock status, and configurator-specific SKUs—for products in 'draft' or 'private' states. This effectively bypasses standard WordPress post-visibility controls. The issue is fixed in version 1.7.3.
Affected products
- Unknown Product Configurator for WooCommerce < 1.7.3
Timeline
- 2026-06-10: disclosed: Initial public disclosure by WPScan
- 2026-06-10: patched: Fix released in version 1.7.3
- 2026-07-01: advisory: NVD publication date