Description
Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Broken Access Control leading to unauthorized actions within WordPress sites
Action: Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to perform actions normally restricted to privileged users. Because the flaw stems from incorrectly configured access control security levels, an unauthorized user could manipulate product bundle settings or access sensitive configuration data. The weakness is categorized as CWE-862, indicating improper restriction of privileges.

Affected Systems

Any WordPress installation that uses the YITH WooCommerce Product Bundles plugin version 2.29.0 or earlier is affected. The issue applies to all releases from the earliest version through 2.29.0. Users employing newer releases such as 2.30.0 or higher are not impacted.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity that can be leveraged by individuals who can reach the plugin’s administrative endpoints. Since the EPSS score is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, the current exploitation probability appears low. Nonetheless, the attack path requires only that an attacker identify the relevant administrative interface, making the vulnerability somewhat easy to target once the target is known.

Generated by OpenCVE AI on October 8, 2026 at 15:07 UTC.

Remediation

Vendor Solution

Update the WordPress YITH WooCommerce Product Bundles plugin to the latest available version (at least 2.30.0).


OpenCVE Recommended Actions

  • Update the YITH WooCommerce Product Bundles plugin to version 2.30.0 or later
  • Configure role permissions so that only administrators can access bundle editing features
  • Verify the configuration by attempting to perform bundle actions as a non-admin to confirm restrictions

Generated by OpenCVE AI on October 8, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.
Title WordPress YITH WooCommerce Product Bundles plugin <= 2.29.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T17:02:33.651Z

Reserved: 2026-10-06T00:18:26.656Z

Link: CVE-2026-105878

cve-icon Vulnrichment

Updated: 2026-10-08T17:02:13.905Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:13.187

Modified: 2026-10-08T17:24:11.230

Link: CVE-2026-105878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:15:12Z

Weaknesses