Impact
The WPC Name Your Price for WooCommerce plugin, in versions before 2.2.5, fails to enforce its server‑side price allowlist for products configured in "Select" price mode due to a lack of input validation and improper handling of price data (CWE‑472). An unauthenticated visitor can submit an arbitrary price that is lower than the merchant‑defined allowed prices, add the product to the cart, and complete a real order at that price. The attack does not grant code execution or access to privileged data, but it can cause substantial financial loss by undercutting legitimate pricing. This is a business‑logic flaw that bypasses the intended pricing controls.
Affected Systems
All installations of the WPC Name Your Price for WooCommerce WordPress plugin older than version 2.2.5 are affected. The vulnerability applies to any release before the 2.2.5 fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of < 1% reflects a very low exploitation probability, yet the vulnerability can still be triggered by a simple unauthenticated HTTP request to the shop’s add‑to‑cart endpoint. The vulnerability is not listed in CISA’s KEV catalog, so no confirmed exploits are publicly known. Because it can be automated and does not require privileged credentials, the financial risk to merchants remains significant despite the low probability of exploitation.
OpenCVE Enrichment