๐Ÿ” CVE Alert

CVE-2026-16620

HIGH 7.5

WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.

Vendor unknown
Product wpc name your price for woocommerce
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpc name your price for woocommerce

Be the first to know when new high vulnerabilities affecting unknown wpc name your price for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / WPC Name Your Price for WooCommerce
0 < 2.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/71e6ccc0-5626-4cce-986e-5591f5df92bd/

Credits

Muni Nitish Kumar Yaddala WPScan