Impact
The Advanced Product Fields (Product Addons) for WooCommerce plugin contains an improper input validation flaw in the validate_cart_data function. This flaw allows attackers who are not logged in to manipulate the add‑to‑cart request and bypass required paid addons. As a result, they can complete a purchase at the base product price, effectively stealing products by paying only a fraction of the intended total. The weakness is a classic input validation error (CWE‑20).
Affected Systems
The vulnerability affects the maartenbelmans Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress, all versions up to and including 1.6.21. A partial patch was applied in 1.6.19, but the flaw remains until a full fix in a later version.
Risk and Exploitability
With a CVSS score of 7.5 this issue is considered high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers do not need to authenticate and can exploit the flaw by sending a crafted HTTP POST to the WooCommerce add‑to‑cart endpoint, manipulating addon data to remove or skip required paid options. Because the exploit works remotely over the public web interface, the risk to all site owners is considerable, especially for shops relying on paid addons for revenue.
OpenCVE Enrichment