CVE-2026-93508
WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.
| Vendor | unknown |
| Product | wc fields factory |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wc fields factory
Be the first to know when new unknown vulnerabilities affecting unknown wc fields factory are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WC Fields Factory
0 < 4.1.11
References
Credits
Farid Narimanov WPScan