CVE-2026-32457
Description
Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Product Fields (Product Addons) for WooCommerce: from n/a through <= 1.6.18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Advanced Product Fields for WooCommerce plugin allows unauthenticated access to restricted functionality, potentially exploited in mass campaigns.
The vulnerability is a missing authorization check in the Advanced Product Fields (Product Addons) for WooCommerce plugin, affecting versions up to and including 1.6.18. The plugin fails to properly enforce access control security levels, allowing unauthenticated users to execute functions that should require higher privileges [1].
An attacker can exploit this by sending crafted HTTP requests to the WordPress site without any authentication. The attack surface is broad, as the plugin is widely used, and no special network position is required. The vulnerability is classified as a broken access control issue, which can be leveraged in automated mass-exploit campaigns targeting thousands of sites [1].
The impact is considered low severity (CVSS 5.3) and unlikely to be exploited in targeted attacks, but the potential for widespread abuse exists. An attacker could manipulate product fields, potentially leading to data corruption or privilege escalation within the WooCommerce environment [1].
Mitigation is straightforward: update the plugin to version 1.6.19 or later, which includes the necessary authorization checks. Patchstack users can enable auto-updates for vulnerable plugins. If immediate updating is not possible, consulting a hosting provider or web developer is recommended [1].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.6.18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.