216.73.216.233

CVE-2025-12115

· Published 31/10/2025 10:15 · Modified 31/10/2025 10:15

Labels: CVE-2025-12115 2025-10-31CVE-2025-12115CWE-602[email protected]

Essential information

Published
31/10/2025 10:15
Modified
31/10/2025 10:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / woocommerce cpe:2.3:a:wordpress:woocommerce:<2.1.9:*:*:*:*:wordpress:*:*

References