๐Ÿ” CVE Alert

CVE-2026-93508

UNKNOWN 0.0

WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.

Vendor unknown
Product wc fields factory
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wc fields factory

Be the first to know when new unknown vulnerabilities affecting unknown wc fields factory are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WC Fields Factory
0 < 4.1.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a927f6d6-90d8-4b91-aed4-f5f53d2b5c64/

Credits

Farid Narimanov WPScan