What is CVE-2026-16620?
This vulnerability exists because the WPC Name Your Price for WooCommerce WordPress plugin fails to enforce its server-side price allowlist in "Select" mode. This allows an unauthenticated visitor to add a product to the cart at an arbitrary value below the merchant-defined allowed prices. Versions before 2.2.5 are affected, and updating to the latest version is recommended.
Azərbaycanca: Bu boşluq WPC Name Your Price for WooCommerce WordPress plaginində server tərəfində qiymət icazə siyahısının "Select" rejimində tətbiq edilməməsindən qaynaqlanır. Bu, autentifikasiya olunmamış ziyarətçiyə məhsulu icazə verilən qiymətdən aşağı ixtiyari dəyərlə səbətə əlavə etməyə imkan yaradır. Plagində 2.2.5 versiyasından əvvəlki versiyalar təsirlənir, administratorlərə ən yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
How is the CVE-2026-16620 vulnerability exploited in the WPC Name Your Price for WooCommerce plugin?
This vulnerability exists because the server-side price allowlist is not enforced in 'Select' mode. An unauthenticated visitor can add a product to the cart at an arbitrary value below the merchant-defined allowed prices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.