Junglewise Threat Intelligence

CVE-2026-2996: Advanced Product Fields for WooCommerce improper input validation in cart processing

CVE-2026-2996 · Severity: high · CVSS 7.5 · Published 2026-08-22

Vendors: Wordpress.

Executive brief

The Advanced Product Fields (Product Addons) for WooCommerce is a WordPress plugin that allows merchants to offer customizable paid add-ons for products. A flaw in cart validation logic allows unauthenticated attackers to bypass payment for required paid addons and purchase products at a reduced price, directly impacting revenue and enabling product theft.

Technical details

The plugin contains a logic flaw in the 'validate_cart_data' function that fails to properly validate required paid addon pricing during cart checkout. This improper input validation vulnerability allows unauthenticated, network-reachable attackers to circumvent addon payment requirements and complete purchases for only the base product price. By manipulating cart data, attackers can effectively steal products worth significantly more than what they pay. A partial patch was released in version 1.6.19, but the vulnerability persists in all versions up to and including 1.6.21.

Affected products

  • WordPress Advanced Product Fields for WooCommerce up to and including 1.6.21

Timeline

  • 2026-08-22: disclosed

References