Unrated severityNVD Advisory· Published Sep 23, 2026
CVE-2026-88929
CVE-2026-88929
Description
The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.