Executive brief
A vulnerability exists in the Product Price by Formula for WooCommerce plugin, which is used by online stores to calculate custom product pricing. An attacker could exploit this flaw to bypass security checks and potentially modify pricing or configuration settings without authorization. This could lead to financial loss through incorrect product pricing or unauthorized changes to store operations.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the ProWCPlugins Product Price by Formula for WooCommerce plugin through version 2.5.6. The issue stems from incorrectly configured access control security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this lack of authorization checks to execute actions that should be restricted to higher-privileged users. Depending on the specific function exposed, this could allow for unauthorized modification of product pricing formulas or other plugin settings. As of the advisory date, no official patch has been released.
Affected products
- ProWCPlugins Product Price by Formula for WooCommerce <= 2.5.6
Timeline
- 2026-01-19: other: Vulnerability reported by researcher
- 2026-02-18: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD