<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Advanced Product Fields (Product Addons) for WooCommerce - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/advanced-product-fields-product-addons-for-woocommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 22 Aug 2026 15:30:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/advanced-product-fields-product-addons-for-woocommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Checkout Price Bypass in Advanced Product Fields for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-08-woocommerce-addon-bypass/</link><pubDate>Sat, 22 Aug 2026 15:30:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-woocommerce-addon-bypass/</guid><description>The Advanced Product Fields for WooCommerce plugin for WordPress is vulnerable to improper input validation, allowing unauthenticated users to bypass mandatory paid add-ons during checkout.</description><content:encoded><![CDATA[<p>The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is susceptible to a logic flaw within the 'validate_cart_data' function, impacting all versions up to and including 1.6.21. This vulnerability stems from improper input validation, which can be exploited by unauthenticated attackers to manipulate the checkout process. By crafting specific requests, an attacker can bypass the validation requirements for mandatory paid product add-ons. Consequently, users can complete purchases at the base product price, effectively circumventing the intended pricing structure and causing financial loss to the merchant. While a partial patch was introduced in version 1.6.19, the vulnerability persists in version 1.6.21, necessitating an immediate update to the latest available patched version.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this flaw allows attackers to purchase products without paying for required add-ons, resulting in direct revenue loss for store operators. Given that this exploit is accessible to unauthenticated users, it poses a significant risk to any e-commerce site using the affected plugin for variable product pricing.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Advanced Product Fields (Product Addons) for WooCommerce plugin to the latest version beyond 1.6.21 immediately.</li>
<li>Review WooCommerce order logs for inconsistencies where the total cart value is significantly lower than the sum of base product costs and required add-on configurations.</li>
<li>Enable verbose logging for the checkout process and monitor for anomalous HTTP POST requests to the WooCommerce cart validation endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>