Description
Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Modification
Action: Upgrade
AI Analysis

Impact

A missing authorization flaw in the ProWCPlugins Product Price by Formula for WooCommerce plugin permits the exploitation of incorrectly configured access control security levels. An attacker could use this weakness to access or modify plugin settings, product pricing data, or other privileged functions without proper authentication, potentially altering product prices or exposing sensitive information. The vulnerability is fundamentally a broken access control weakness, identified as CWE‑862.

Affected Systems

Any WordPress site running ProWCPlugins Product Price by Formula for WooCommerce version 2.5.6 or earlier is affected. The plugin implements pricing logic that, when accessed without correct permissions, allows unauthorized changes to product prices or related configurations.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, with an EPSS score below 1% suggesting that exploitation is relatively uncommon. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time. Based on the plugin’s nature, the likely attack vector is remote, where an unauthenticated or low‑privilege user could interact with the plugin’s endpoints to manipulate pricing data. Because the flaw stems from missing authorization checks, it does not require advanced skills but does need the target site to have the vulnerable plugin installed and exposed.

Generated by OpenCVE AI on April 9, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Product Price by Formula for WooCommerce plugin to the latest version that addresses the access control issue.

Generated by OpenCVE AI on April 9, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Thu, 09 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Prowcplugins
Prowcplugins product Price By Formula For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Prowcplugins
Prowcplugins product Price By Formula For Woocommerce
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through <= 2.5.6.
Title WordPress Product Price by Formula for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Prowcplugins Product Price By Formula For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:04.047Z

Reserved: 2026-04-07T10:57:53.260Z

Link: CVE-2026-39662

cve-icon Vulnrichment

Updated: 2026-04-09T15:04:00.807Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:37.360

Modified: 2026-04-29T10:17:37.480

Link: CVE-2026-39662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:40:39Z

Weaknesses