Executive brief
The WowAddons plugin for WordPress, which provides additional product features for e-commerce sites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and perform actions they should not be permitted to do. This could lead to unauthorized modifications of site content or settings, potentially disrupting business operations.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the WPXPO WowAddons (product-addons) plugin for WordPress in versions up to and including 1.6.8. The flaw stems from a failure to properly validate user permissions or security levels within certain plugin functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to execute actions reserved for higher-privileged users. The issue is addressed in version 1.6.9.
Affected products
- WPXPO WowAddons (product-addons) <= 1.6.8
Timeline
- 2026-04-30: other: Reported by researcher dodoh4t
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD
- 2026-07-13: patched: Patch confirmed available in version 1.6.9