Executive brief
Sale Booster, a WordPress plugin for WooCommerce product badges and promotional countdowns, fails to verify that products are published before displaying them. An attacker can view the titles, descriptions, and prices of draft, pending, and private products without logging in, exposing unreleased pricing and product plans.
Technical details
The plugin does not check publication status before returning product details via unauthenticated REST API or direct queries (CWE-200: Exposure of Sensitive Information). Attackers can enumerate non-public products and extract metadata without authentication. The vulnerability is fixed in version 7.5.2.
Affected products
- WooCommerce Sale Booster 7.0.0 through 7.5.1
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Fixed in version 7.5.2