Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93507 1 Wordpress-extensions 1 Wc Fields Factory 2026-09-28 3.3 Low
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
CVE-2026-93508 1 Wordpress-extensions 1 Wc Fields Factory 2026-09-28 8.1 High
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.