Description
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data disclosure of non-public product information
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin prior to version 7.5.2 because it does not enforce a check on product publication status before returning product details. As a result, any visitor, without authentication, can access the title, description and price of draft, pending and private products, exposing confidential business information and potentially revealing pricing strategies and inventory status.

Affected Systems

All WordPress sites using the Product Badge, Label, Countdown Timer for WooCommerce plugin in the 7.0.0 through 7.5.1 range are impacted. The issue affects only the plugin and not the WordPress core or WooCommerce itself. The affected versions are all those released before 7.5.2.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an unauthenticated HTTP request to the plugin’s product detail endpoints, meaning that an attacker only needs to know or guess a product identifier. No additional credentials or elevated privileges are required.

Generated by OpenCVE AI on September 23, 2026 at 14:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Product Badge, Label, Countdown Timer for WooCommerce plugin to version 7.5.2 or later to rectify the non-public product disclosure flaw.
  • If an immediate update cannot be applied, disable the plugin or block its endpoints from unauthenticated access to prevent accidental exposure of draft or private product data.
  • Monitor site logs and perform regular scans to confirm that no unauthenticated URLs expose product details after remediation.

Generated by OpenCVE AI on September 23, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
Title Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:53:41.407Z

Reserved: 2026-09-10T14:12:11.568Z

Link: CVE-2026-88929

cve-icon Vulnrichment

Updated: 2026-09-23T10:34:22.095Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:04.860

Modified: 2026-09-23T11:17:16.317

Link: CVE-2026-88929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor