Product Configurator for WooCommerce <= 1.7.2 - Unauthenticated Private/Draft Product Data Disclosure
medium
The Product Configurator for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.7.2. This is due to missing authorization check in the pc_get_data AJAX handler allowing unauthenticated access to non-published product configurator data. This makes it poss...
- CVSS:
- 5.3
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.3
- Disclosed:
- Jun 10, 2026
CVE-2026-11568 on NVD →
Product Configurator for WooCommerce <= 1.4.4 - Cross-Site Request Forgery
medium
The Product Configurator for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they c...
- CVSS:
- 4.3
- Affected:
- up to 1.4.4
- Fixed in:
- 1.5.0
- Disclosed:
- Jul 30, 2025
CVE-2025-54674 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database