CVE 7.5 HIGH

WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration_CVE-2025-12115

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.

Basic Information

ID CVE-2025-12115
Source Wordfence
Published Oct 31, 2025 at 09:27
Modified Oct 31, 2025 at 18:43

Affected Product

Vendor wpclever
Product WPC Name Your Price for WooCommerce
Version *
Affected Versions wpclever WPC Name Your Price for WooCommerce *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.