Vulnerabilities / PPOM for WooCommerce / WPSEC-2026-0678
PPOM for WooCommerce <= 34.0.10 - Unauthenticated Price Manipulation via 'price_matrix_found' Parameter
Medium 5.3
CWE-472Fixed in 34.0.11
- ID
- WPSEC-2026-0678
- Plugin
- PPOM – Product Addons & Custom Fields for WooCommerce (woocommerce-product-addon)
- Affected
- all versions before 34.0.11
- Remediation
- Update to 34.0.11 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-472
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- PPOM for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 34.0.10. The cart pricing logic read the price matrix from the shopper-posted 'ppom' payload, which was stored in the cart item without validation and was only replaced for products that have a price matrix field. This makes it possible for unauthenticated attackers to set their own price for products that use PPOM fields but no price matrix field when adding them to the cart.
References
- https://wpsec.com/vuln/WPSEC-2026-0678/
- https://plugins.svn.wordpress.org/woocommerce-product-addon/tags/34.0.11/
- https://wordpress.org/plugins/woocommerce-product-addon/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS