CVE-2026-11364Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and AttributeController classes, which are bound to the 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, edit, and delete arbitrary product specification groups and attributes (taxonomy terms in the 'spec-group' and attribute taxonomies), corrupting business data and impacting the site's frontend display.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-27: 3Technical Details · 2026-06-27: 206-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-11364 The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and inclu… https://www.cve.org/CVERecord?id=CVE-2026-11364 ----- Traducción: CVE-2026-11364 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑11364 affecting the WooCommerce plugin, notes data integrity risks, and links to the official CVE record, but provides no PoC, exploit, patch, or active exploitation details.

    0001034
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-11364 The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and inclu… https://www.cve.org/CVERecord?id=CVE-2026-11364

    Post summary

    The WooCommerce product specifications plugin is disclosed to allow unauthorized data modification, creation, and deletion, with no PoC, exploits, or patch details noted.

    00010711
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-11364 Unauthorized Data Modification in WooCommerce Product Spe... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11364 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The text lists CVE-2026-11364 and provides a link to a detail page, but offers no technical, exploit, or mitigation information.

    00010123
    4.1K followersView on X

Explore more