Junglewise Threat Intelligence

CVE-2026-48883: WPClever WPC Product Bundles for WooCommerce broken access control

CVE-2026-48883 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

WPC Product Bundles for WooCommerce is a WordPress plugin used to create and manage product packages on e-commerce sites. A security flaw allows unauthenticated visitors to bypass access controls, potentially allowing them to perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes to product configurations or store data, impacting the integrity of the online shop.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) within the WPC Product Bundles for WooCommerce plugin. It stems from a failure to implement proper permission checks or nonce validation on certain functions, allowing an unauthenticated remote attacker to execute privileged actions. The attack vector is network-based with low complexity and requires no user interaction. While the CVSS score is 7.5 (High), the impact is primarily on integrity (I:H) rather than confidentiality or availability. The issue is resolved in version 8.5.4.

Affected products

  • WPClever WPC Product Bundles for WooCommerce <= 8.5.3

Timeline

  • 2026-05-13: other: Reported by Jakub Herman
  • 2026-06-01: patched: Version 8.5.4 released
  • 2026-06-15: disclosed: NVD publication date

References