# YITH WooCommerce Product Add-Ons <= 4.34.0 - Unauthenticated Information Exposure of Unpublished Product Prices

- **ID:** WPSEC-2026-0494
- **Plugin:** YITH WooCommerce Product Add-Ons (`yith-woocommerce-product-add-ons`), https://wordpress.org/plugins/yith-woocommerce-product-add-ons/
- **Affected versions:** from 2.0.3 before 4.34.1
- **Fixed in:** 4.34.1 (Update to 4.34.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/yith-woocommerce-product-add-ons
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0494/

## Description

The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.34.0. This is due to the 'live_print_blocks', 'update_totals_with_suffix' and 'get_default_variation_price' AJAX actions accepting an arbitrary product ID and returning that product's price without checking that the product is published. This makes it possible for unauthenticated attackers to retrieve the prices of unpublished (draft, pending, scheduled or private) products.

## References

- https://wpsec.com/vuln/WPSEC-2026-0494/
- https://plugins.svn.wordpress.org/yith-woocommerce-product-add-ons/tags/4.34.1/
- https://wordpress.org/plugins/yith-woocommerce-product-add-ons/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0494/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
