CVE-2026-93508 PUBLISHED

WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via AJAX

Assigner: WPScan
Reserved: 18.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.

Product Status

Vendor Unknown
Product WC Fields Factory
Versions Default: unaffected
  • affected from 0 to 4.1.11 (excl.)

Credits

  • Farid Narimanov finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE