PatchSiren

WPC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPC CVE published 2026-08-06

CVE-2026-16620

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in 'Select' price mode. This allows an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price, resulting in revenue loss or underpriced orders. This issue is di [truncated]