HIGH
WPC
CVE published 2026-08-06
CVE-2026-16620
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in 'Select' price mode. This allows an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price, resulting in revenue loss or underpriced orders. This issue is di [truncated]