VYPR
Unrated severityNVD Advisory· Published Sep 23, 2026

CVE-2026-88929

CVE-2026-88929

Description

The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.