Description
Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows attackers to access administrative functions of the EDGARROJAS Extra Product Options Builder for WooCommerce plugin without proper permission. This could enable unauthorized manipulation of product option settings and compromise the integrity of a WooCommerce store. The weakness is classified as CWE‑862 (Missing Authorization).

Affected Systems

The vulnerability affects sites that have the EDGARROJAS Extra Product Options Builder for WooCommerce plugin version 1.2.167 or earlier. No other vendors or products are reported as affected by this CVE.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS of <1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that to the plugin’s administrative endpoints, potentially from any user with network access to the WordPress installation, to bypass standard authorization checks.

Generated by OpenCVE AI on July 31, 2026 at 12:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to the latest version released by the vendor; the fix is included in subsequent releases beyond 1.2.167.
  • If the plugin is not required for the site, remove or disable it to eliminate the attack surface.
  • Enforce strict role‑based access control for WooCommerce product option management, ensuring only administrators have the capability to modify options.
  • Enable logging for all product option changes and review logs regularly for unauthorized attempts.
  • Apply web‑application firewall rules to restrict access to the plugin’s administrative URLs to authorized IP addresses.

Generated by OpenCVE AI on July 31, 2026 at 12:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.
Title WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:53.389Z

Reserved: 2026-06-24T12:46:01.633Z

Link: CVE-2026-57390

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:31.134Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses