Junglewise Threat Intelligence

CVE-2026-57664: VillaTheme Bopo WooCommerce Product Bundle Builder sensitive data exposure

CVE-2026-57664 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Vendors: VillaTheme.

Executive brief

Bopo is a WordPress plugin used by e-commerce sites to create custom product bundles in WooCommerce. A security flaw in this plugin allows unauthorized individuals to access sensitive system information that should be restricted. This exposure could provide attackers with technical details needed to facilitate further, more complex attacks against the website.

Technical details

The Bopo – WooCommerce Product Bundle Builder plugin for WordPress is vulnerable to Sensitive Data Exposure (CWE-497) in versions up to 1.1.6. The vulnerability stems from improper control of sensitive system information, allowing unauthenticated or low-privileged users to view data that is normally restricted. While the CVSS vector provided by the CNA (Patchstack) indicates a 'Low' privilege requirement (PR:L), the advisory title and description explicitly state the vulnerability is 'Unauthenticated.' An attacker can exploit this over the network without user interaction to gather information that could assist in further exploitation. The issue is resolved in version 1.2.0.

Affected products

  • VillaTheme Bopo – WooCommerce Product Bundle Builder <= 1.1.6

Timeline

  • 2026-02-21: other: Reported by Bao - BlueRock
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Publicly published by Patchstack and NVD
  • 1.2.0: patched: Vulnerability fixed in version 1.2.0

References