VYPR
Medium severity5.3NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32457

CVE-2026-32457

Description

Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <= 1.6.18.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Advanced Product Fields for WooCommerce plugin allows unauthenticated access to restricted functionality, potentially exploited in mass campaigns.

The vulnerability is a missing authorization check in the Advanced Product Fields (Product Addons) for WooCommerce plugin, affecting versions up to and including 1.6.18. The plugin fails to properly enforce access control security levels, allowing unauthenticated users to execute functions that should require higher privileges [1].

An attacker can exploit this by sending crafted HTTP requests to the WordPress site without any authentication. The attack surface is broad, as the plugin is widely used, and no special network position is required. The vulnerability is classified as a broken access control issue, which can be leveraged in automated mass-exploit campaigns targeting thousands of sites [1].

The impact is considered low severity (CVSS 5.3) and unlikely to be exploited in targeted attacks, but the potential for widespread abuse exists. An attacker could manipulate product fields, potentially leading to data corruption or privilege escalation within the WooCommerce environment [1].

Mitigation is straightforward: update the plugin to version 1.6.19 or later, which includes the necessary authorization checks. Patchstack users can enable auto-updates for vulnerable plugins. If immediate updating is not possible, consulting a hosting provider or web developer is recommended [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.