Description
The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.
Published: 2026-07-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Product Configurator for WooCommerce WordPress plugin before version 1.7.3 fails to perform any authorization or post‑status checks before returning product data through a public AJAX action named pc_get_data. An attacker can supply a product ID and receive sensitive product attributes such as title, price, weight, stock status, and configurator option pricing or SKUs, even when the product is marked private or draft. This bypasses the WordPress post‑visibility controls and results in a confidentiality breach.

Affected Systems

Any WordPress site that installs Product Configurator for WooCommerce and uses a version older than 1.7.3 is affected. The extension is listed under the vendor "Unknown" and the plugin name "Product Configurator for WooCommerce"; no additional vendor or product details are provided.

Risk and Exploitability

The vulnerability is exploitable by anyone with unauthenticated HTTP access to the site, making the attack vector remote and straightforward. Although no EPSS score is available, the lack of authentication checks indicates a high potential for exploitation. The issue is not currently listed in the CISA KEV catalog, but the data exposure severity warrants immediate attention.

Generated by OpenCVE AI on July 1, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin version, 1.7.3 or newer, which contains the authorization fix.
  • If an upgrade is not immediately possible, restrict access to the pc_get_data AJAX endpoint to authenticated users via .htaccess or a firewall rule.
  • Disable or remove the Product Configurator for WooCommerce plugin until a patched version is available.

Generated by OpenCVE AI on July 1, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. WordPress post-visibility controls are bypassed.
Title Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-01T10:19:26.363Z

Reserved: 2026-06-08T09:06:54.676Z

Link: CVE-2026-11568

cve-icon Vulnrichment

Updated: 2026-07-01T10:19:19.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T08:45:15Z

Weaknesses