Executive brief
The Advanced Product Fields (Product Addons) for WooCommerce is a WordPress plugin that allows merchants to offer customizable paid add-ons for products. A flaw in cart validation logic allows unauthenticated attackers to bypass payment for required paid addons and purchase products at a reduced price, directly impacting revenue and enabling product theft.
Technical details
The plugin contains a logic flaw in the 'validate_cart_data' function that fails to properly validate required paid addon pricing during cart checkout. This improper input validation vulnerability allows unauthenticated, network-reachable attackers to circumvent addon payment requirements and complete purchases for only the base product price. By manipulating cart data, attackers can effectively steal products worth significantly more than what they pay. A partial patch was released in version 1.6.19, but the vulnerability persists in all versions up to and including 1.6.21.
Affected products
- WordPress Advanced Product Fields for WooCommerce up to and including 1.6.21
Timeline
- 2026-08-22: disclosed