Vulnerabilities / YITH WooCommerce Product Add-Ons / WPSEC-2026-0494
YITH WooCommerce Product Add-Ons <= 4.34.0 - Unauthenticated Information Exposure of Unpublished Product Prices
Medium 5.3
CWE-200Fixed in 4.34.1
- ID
- WPSEC-2026-0494
- Plugin
- YITH WooCommerce Product Add-Ons (yith-woocommerce-product-add-ons)
- Affected
- from 2.0.3 before 4.34.1
- Remediation
- Update to 4.34.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- YITH WooCommerce Product Add-Ons on WPSec AttackSurface
- Fix released
- Published
Description
The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.34.0. This is due to the 'live_print_blocks', 'update_totals_with_suffix' and 'get_default_variation_price' AJAX actions accepting an arbitrary product ID and returning that product's price without checking that the product is published. This makes it possible for unauthenticated attackers to retrieve the prices of unpublished (draft, pending, scheduled or private) products.
References
- https://wpsec.com/vuln/WPSEC-2026-0494/
- https://plugins.svn.wordpress.org/yith-woocommerce-product-add-ons/tags/4.34.1/
- https://wordpress.org/plugins/yith-woocommerce-product-add-ons/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS