VYPR
Medium severity5.4NVD Advisory· Published Oct 1, 2026

CVE-2026-12241

CVE-2026-12241

Description

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_meta_boxes' function in all versions up to, and including, 2.51. This makes it possible for authenticated attackers, with Contributor-level access and above, to create AWS labels that are rendered without proper escaping. The vulnerability was partially patched in version 2.46.

Affected products

1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.