Executive brief
Themeisle PPOM for WooCommerce is a WordPress plugin used to add custom fields and options to product pages. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to product configurations or disruptions to the online store's operations.
Technical details
An improper access control vulnerability (CWE-284) exists in the Themeisle PPOM for WooCommerce plugin for WordPress. The flaw stems from incorrectly configured access control security levels, which fail to properly validate authorization or authentication tokens for certain functions. An unauthenticated remote attacker can exploit this vulnerability to execute actions that should require higher privileges, potentially impacting the integrity and availability of the plugin's data. The issue affects versions up to and including 33.0.18 and is resolved in version 34.0.0.
Affected products
- Themeisle PPOM for WooCommerce n/a through 33.0.18
Timeline
- 2026-04-29: other: Reported by HaiND
- 2026-06-25: advisory: Published by Patchstack and NVD
- 2026-06-25: patched: Fixed in version 34.0.0