4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and AttributeController classes, which are bound to the 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create, edit, and delete arbitrary product specification groups and attributes (taxonomy terms in the 'spec-group' and attribute taxonomies), corrupting business data and impacting the site's frontend display.
Basic Information
ID
CVE-2026-11364
Source
Wordfence
Published
Jun 27, 2026 at 06:50
Affected Product
Vendor
dornaweb
Product
Product Specifications for Woocommerce
Affected Versions
dornaweb Product Specifications for Woocommerce 0
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/38318605-40f7-4676-b409-f98a6c27cbfe
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.9/src/EntityUpdater/AttributeGroupController.php
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.9/src/EntityUpdater/AttributeController.php
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.9/src/EntityUpdater/Module.php
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.7/src/EntityUpdater/AttributeGroupController.php
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.7/src/EntityUpdater/AttributeController.php
- plugins.trac.wordpress.org /browser/product-specifications/tags/0.8.7/src/EntityUpdater/Module.php
- plugins.trac.wordpress.org /changeset