{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/advanced-product-fields-product-addons-for-woocommerce/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-2996"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Advanced Product Fields (Product Addons) for WooCommerce"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is susceptible to a logic flaw within the 'validate_cart_data' function, impacting all versions up to and including 1.6.21. This vulnerability stems from improper input validation, which can be exploited by unauthenticated attackers to manipulate the checkout process. By crafting specific requests, an attacker can bypass the validation requirements for mandatory paid product add-ons. Consequently, users can complete purchases at the base product price, effectively circumventing the intended pricing structure and causing financial loss to the merchant. While a partial patch was introduced in version 1.6.19, the vulnerability persists in version 1.6.21, necessitating an immediate update to the latest available patched version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this flaw allows attackers to purchase products without paying for required add-ons, resulting in direct revenue loss for store operators. Given that this exploit is accessible to unauthenticated users, it poses a significant risk to any e-commerce site using the affected plugin for variable product pricing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Advanced Product Fields (Product Addons) for WooCommerce plugin to the latest version beyond 1.6.21 immediately.\u003c/li\u003e\n\u003cli\u003eReview WooCommerce order logs for inconsistencies where the total cart value is significantly lower than the sum of base product costs and required add-on configurations.\u003c/li\u003e\n\u003cli\u003eEnable verbose logging for the checkout process and monitor for anomalous HTTP POST requests to the WooCommerce cart validation endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T15:30:55Z","date_published":"2026-08-22T15:30:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-addon-bypass/","summary":"The Advanced Product Fields for WooCommerce plugin for WordPress is vulnerable to improper input validation, allowing unauthenticated users to bypass mandatory paid add-ons during checkout.","title":"Unauthenticated Checkout Price Bypass in Advanced Product Fields for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-08-woocommerce-addon-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Advanced Product Fields (Product Addons) for WooCommerce","version":"https://jsonfeed.org/version/1.1"}