Junglewise Threat Intelligence

CVE-2026-57390: EDGARROJAS Extra Product Options Builder for WooCommerce missing authorization

CVE-2026-57390 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Executive brief

A security vulnerability exists in the Extra Product Options Builder for WooCommerce, a WordPress plugin used to add custom fields and options to online store products. Due to missing authorization checks, an unauthorized user could potentially modify product settings or disrupt store operations. This could lead to incorrect product configurations or minor service disruptions on the affected e-commerce site.

Technical details

The Extra Product Options Builder for WooCommerce plugin (versions up to and including 1.2.167) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to perform actions that should be restricted to higher-privileged users. The vulnerability stems from a failure to validate user permissions or nonces in specific functions, potentially allowing for unauthorized modification of product fields or settings. The issue is addressed in version 1.2.168.

Affected products

  • EDGARROJAS Extra Product Options Builder for WooCommerce (additional-product-fields-for-woocommerce) <= 1.2.167

Timeline

  • 2026-05-28: disclosed: Reported by VanTastic to Patchstack
  • 2026-07-08: patched: Version 1.2.168 released
  • 2026-07-13: advisory: NVD publication date

References