Description
The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Product Configurator for WooCommerce WordPress plugin before version 1.7.3 does not enforce authorization or validate the post status before returning product data through a public AJAX action. An attacker can supply any product ID, causing the endpoint to reveal sensitive attributes—title, price, weight, stock status, and configurator option pricing or SKUs—of private or draft products. The weakness corresponds to missing authorization checks (CWE‑284 and CWE‑285).

Affected Systems

Any WordPress site that WooCommerce plugin with a version older than 1.7.3 is affected; the vendor is unspecified.

Risk and Exploitability

The public AJAX endpoint can be accessed by unauthenticated users, so the attack vector is likely external, web‑based requests. The CVSS score of 7.5 signals a moderate‑high severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint lacks authentication checks, sites that expose private or draft product data are at significant risk of disclosing confidential product details.

Generated by OpenCVE AI on July 21, 2026 at 15:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 1.7.3 or later of the Product Configurator for WooCommerce plugin.
  • If an upgrade cannot be performed, enforce authentication on the pc_get_data AJAX endpoint via server‑side rules or a firewall, restricting access to logged‑in users.
  • Remove or deactivate the Product Configurator for WooCommerce plugin until a patched version is available.

Generated by OpenCVE AI on July 21, 2026 at 15:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-285

Fri, 17 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Thu, 09 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-285

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-285

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.
Title Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:19:26.363Z

Reserved: 2026-06-08T09:06:54.676Z

Link: CVE-2026-11568

cve-icon Vulnrichment

Updated: 2026-07-01T10:19:19.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-285

    Improper Authorization