PPOM for WooCommerce <= 34.0.10 - Unauthenticated Price Manipulation via 'price_matrix_found' Parameter

Medium 5.3 CWE-472Fixed in 34.0.11
ID
WPSEC-2026-0678
Plugin
PPOM – Product Addons & Custom Fields for WooCommerce (woocommerce-product-addon)
Affected
all versions before 34.0.11
Remediation
Update to 34.0.11 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-472
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
PPOM for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 34.0.10. The cart pricing logic read the price matrix from the shopper-posted 'ppom' payload, which was stored in the cart item without validation and was only replaced for products that have a price matrix field. This makes it possible for unauthenticated attackers to set their own price for products that use PPOM fields but no price matrix field when adding them to the cart.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0