VYPR

WPC Name Your Price for WooCommerce

by WordPress

CVEs (2)

  • CVE-2026-16620HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the…

  • CVE-2025-12115HigOct 31, 2025
    risk 0.49cvss 7.5epss 0.00

    The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a…