CVE-2026-2996General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Ciberseguridad LATAM@CibersegLATAM
    General

    CVE-2026-2996 afecta todas las versiones hasta 1.6.21 de Advanced Product Fields y permite a atacantes sin credenciales saltear addons pagos obligatorios.

    Post summary

    This Spanish tweet merely indicates that CVE-2026-2996 affects all Advanced Product Fields versions up to 1.6.21, permitting attackers without credentials to bypass mandatory paid addons, with no further exploitation or mitigation details provided.

    10000150
    22.5K followersView on X

Explore more