PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16620 WPC CVE debrief

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in 'Select' price mode. This allows an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price, resulting in revenue loss or underpriced orders. This issue is distinct from CVE-2025-12115.

Vendor
WPC
Product
Name Your Price for WooCommerce
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-07
Advisory published
2026-08-06
Advisory updated
2026-08-07

Who should care

Merchants using WPC Name Your Price for WooCommerce, especially those with products configured in 'Select' price mode, should be aware of this vulnerability and take steps to mitigate it. This includes verifying their plugin version, reviewing and adjusting price allowlists, and monitoring for suspicious activity related to arbitrary pricing. Additionally, security teams and vulnerability management teams should be aware of the potential impact of this vulnerability on their organization's e-commerce platforms and take appropriate measures to protect against exploitation. Platform operators and security teams should review the official advisory and CVE record for further details and guidance on mitigation and remediation efforts.

Technical summary

The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in 'Select' price mode. This allows an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price. The issue is distinct from CVE-2025-12115, which addressed applying a custom price to products where Name Your Price is disabled. Merchants using this plugin, especially those with products in 'Select' price mode, should verify their plugin version and consider updating to version 2.2.5 or later to address this issue. Additional technical details include the need for merchants to review and adjust price allowlists for products in 'Select' price mode and to monitor for suspicious activity related to arbitrary pricing.

Defensive priority

Merchants using WPC Name Your Price for WooCommerce should verify their plugin version and consider updating to version 2.2.5 or later to address this issue.

Recommended defensive actions

  • Verify plugin version and update to 2.2.5 or later
  • Review and adjust price allowlists for products in 'Select' price mode
  • Monitor for suspicious activity related to arbitrary pricing
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details about the vulnerability in the WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5. This vulnerability allows an unauthenticated visitor to add a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price, resulting in revenue loss or underpriced orders. Additional information from the vendor or other sources may be necessary to fully understand the issue, especially regarding the scope of affected products and potential mitigations. Defenders should verify their plugin version, review price allowlists for products in 'Select' price mode, and monitor for suspicious activity related to arbitrary pricing. The vendor's official advisory and CVE record should be consulted for further details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:49.120Z and has not been modified since then.