Description
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.
Published: 2026-08-22
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Maartenbelmans
Maartenbelmans advanced Product Fields Product Addons For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Maartenbelmans
Maartenbelmans advanced Product Fields Product Addons For Woocommerce
Wordpress
Wordpress wordpress

Sat, 22 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19.
Title Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.21 - Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Maartenbelmans Advanced Product Fields Product Addons For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-22T13:27:14.956Z

Reserved: 2026-02-23T00:50:08.677Z

Link: CVE-2026-2996

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T14:16:32.807

Modified: 2026-08-22T14:16:32.807

Link: CVE-2026-2996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T14:30:17Z

Weaknesses