Impact
The WPC Name Your Price for WooCommerce plugin, in versions before 2.2.5, fails to enforce its server‑side price allowlist for products configured in “Select” price mode. An unauthenticated visitor can submit an arbitrary price that is lower than the merchant‑defined allowed prices, add the product to the cart, and complete a real order at that price. The attack does not grant code execution or access to privileged data, but it can cause substantial financial loss by undercutting legitimate pricing. This is a business‑logic flaw that bypasses the intended pricing controls.
Affected Systems
All installations of the WPC Name Your Price for WooCommerce WordPress plugin older than version 2.2.5 are affected. The vulnerability applies to any release before the 2.2.5 fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Because the EPSS score is not available, the exact likelihood of exploitation is unknown, but the vulnerability can be triggered by a simple unauthenticated HTTP request to the shop’s add‑to‑cart endpoint. It is listed as not part of CISA’s KEV catalog, so no confirmed exploits are known publicly. The attack can be automated and does not require privileged credentials, so the risk to merchants with the plugin enabled is significant.
OpenCVE Enrichment