The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress Wpclever Wpclever wpc Name Your Price For Woocommerce |
|
| Vendors & Products |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress Wpclever Wpclever wpc Name Your Price For Woocommerce |
Fri, 31 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to. | |
| Title | WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration | |
| Weaknesses | CWE-602 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-31T09:27:21.530Z
Updated: 2025-10-31T18:43:39.464Z
Reserved: 2025-10-23T15:27:17.832Z
Link: CVE-2025-12115
Updated: 2025-10-31T18:43:33.665Z
Status : Received
Published: 2025-10-31T10:15:49.990
Modified: 2025-10-31T10:15:49.990
Link: CVE-2025-12115
No data.