Junglewise Threat Intelligence

CVE-2026-62136: WP Desk Flexible Quantity , Measurement Price Calculator broken access control

CVE-2026-62136 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Executive brief

The Flexible Quantity – Measurement Price Calculator for WooCommerce is a WordPress plugin that enables dynamic pricing based on product measurements for online stores. An unauthenticated vulnerability allows attackers to bypass access controls and access pages or perform actions they should not be permitted to perform, potentially exposing sensitive data or disrupting store operations.

Technical details

This vulnerability is a broken access control issue (CWE-639) affecting versions 2.3.21 and earlier of the plugin. The vulnerability allows unauthenticated attackers to access restricted functionality or data without proper authorization checks. No specific attack preconditions beyond network access to the affected WordPress site are required. An attacker can view or perform actions they are not entitled to access, such as accessing other users' data or administrative functions. The vulnerability has been patched in version 2.3.22 and later; administrators should update immediately.

Affected products

  • WP Desk Flexible Quantity – Measurement Price Calculator for WooCommerce <=2.3.21

Timeline

  • 2026-08-26: disclosed: Reported by sungbyeongchan
  • 2026-09-10: advisory: Published by Patchstack; early warning sent to customers
  • 2026-09-10: patched: Fixed in version 2.3.22

References