Impact
The Advanced Product Fields (Product Addons) for WooCommerce plugin suffers from a missing or incorrect nonce check in the ‘maybe_duplicate’ function. This flaw allows an unauthenticated attacker to forge a request that duplicates existing product field groups and publishes them, including groups that were in draft or pending state. The impact is confined to the manipulation of product metadata, potentially altering the way product information is displayed to customers, but does not grant code execution or full access to the system.
Affected Systems
WordPress sites using the Advanced Product Fields (Product Addons) for WooCommerce plugin version 1.6.17 or earlier, released by maartenbelmans. Only those specific plugin versions are affected; recent releases beyond 1.6.17 have confirmed mitigation.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk; the EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited real‑world usage. The attack path requires an administrator to be tricked into clicking a forged link, so while the vector exists, operational security practices such as monitoring administrator links and enforcing strong authentication reduce the practical threat.
OpenCVE Enrichment