# PPOM for WooCommerce <= 34.0.10 - Unauthenticated Price Manipulation via 'price_matrix_found' Parameter

- **ID:** WPSEC-2026-0678
- **Plugin:** PPOM – Product Addons & Custom Fields for WooCommerce (`woocommerce-product-addon`), https://wordpress.org/plugins/woocommerce-product-addon/
- **Affected versions:** all versions before 34.0.11
- **Fixed in:** 34.0.11 (Update to 34.0.11 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-472
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-product-addon
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0678/

## Description

The Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 34.0.10. The cart pricing logic read the price matrix from the shopper-posted 'ppom' payload, which was stored in the cart item without validation and was only replaced for products that have a price matrix field. This makes it possible for unauthenticated attackers to set their own price for products that use PPOM fields but no price matrix field when adding them to the cart.

## References

- https://wpsec.com/vuln/WPSEC-2026-0678/
- https://plugins.svn.wordpress.org/woocommerce-product-addon/tags/34.0.11/
- https://wordpress.org/plugins/woocommerce-product-addon/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0678/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
