Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products. | |
| Title | Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:53:41.407Z
Reserved: 2026-09-10T14:12:11.568Z
Link: CVE-2026-88929
Updated: 2026-09-23T10:34:22.095Z
Status : Received
Published: 2026-09-23T06:17:04.860
Modified: 2026-09-23T11:17:16.317
Link: CVE-2026-88929
No data.
OpenCVE Enrichment
Updated: 2026-09-23T14:30:06Z