Add Product Frontend for WooCommerce Security & Risk Analysis

wordpress.org/plugins/add-product-frontend-for-woocommerce

"Add Product Frontend for WooCommerce" is the most popular plugin that add product from frontend page.

90 active installs v1.0.8 PHP 7.4+ WP 5.6+ Updated Sep 1, 2025
add-products-frontendbytes-add-products-frontendproductswoocommercewoocommerce-products
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 11, 2025
Safety Verdict

Is Add Product Frontend for WooCommerce Safe to Use in 2026?

Mostly Safe

Score 79/100

Add Product Frontend for WooCommerce is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Apr 11, 2025Updated 8mo ago
Risk Assessment

The "add-product-frontend-for-woocommerce" plugin version 1.0.8 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling (100% prepared statements) and a high rate of output escaping (87%), significant concerns arise from its attack surface. The presence of 12 AJAX handlers, with a worrying 10 of them lacking authentication checks, presents a substantial risk of unauthorized actions. Furthermore, the taint analysis revealed 2 flows with unsanitized paths, indicating potential for insecure data handling, although thankfully no critical or high-severity issues were flagged in this area.

The plugin's vulnerability history is a major red flag. It has one known CVE, which is currently unpatched and classified as medium severity. The pattern of "Missing Authorization" vulnerabilities in the past, coupled with the current unpatched issue and the significant number of unprotected AJAX endpoints, strongly suggests a recurring problem with securing its entry points. This indicates a potential for attackers to exploit these weaknesses to perform actions they shouldn't be able to.

In conclusion, while the plugin benefits from secure SQL practices and robust output escaping, the high number of unprotected AJAX endpoints and the history of authorization vulnerabilities are critical concerns. The unpatched medium-severity CVE further elevates the risk. Users of this plugin should exercise caution and consider the potential for unauthorized access and execution of actions due to the identified weaknesses.

Key Concerns

  • Unpatched CVE (medium severity)
  • Large attack surface without auth (AJAX)
  • Flows with unsanitized paths (taint analysis)
  • Missing authorization in AJAX handlers
  • Bundled library (Select2) not analyzed for vulns
Vulnerabilities
1 published

Add Product Frontend for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32593medium · 5.3Missing Authorization

Add Product Frontend for WooCommerce <= 1.0.6 - Missing Authorization to Unauthenticated Arbitrary Content Deletion

Apr 11, 2025Unpatched
Version History

Add Product Frontend for WooCommerce Release Timeline

v1.0.8Current1 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Add Product Frontend for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
52
355 escaped
Nonce Checks
3
Capability Checks
19
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

87% escaped407 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
extra_tablenav (admin\partials\plugin-bytes-product-list.php:331)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
10 unprotected

Add Product Frontend for WooCommerce Attack Surface

Entry Points12
Unprotected10

AJAX Handlers 12

authwp_ajax_bytes_admin_delete_productadmin\inc\ajax.php:3
authwp_ajax_bytes_deactivate_feedback_formbytes-add-product-frontend-for-woocommerce.php:166
authwp_ajax_apffw_get_users_by_rolebytes-add-product-frontend-for-woocommerce.php:193
authwp_ajax_bytes_delete_productpublic\inc\bytes-delete-product.php:3
authwp_ajax_bytes_add_product_attributespublic\inc\bytes-product-attributes.php:3
noprivwp_ajax_bytes_add_product_attributespublic\inc\bytes-product-attributes.php:4
authwp_ajax_bytes_product_add_new_attributepublic\inc\bytes-product-attributes.php:6
noprivwp_ajax_bytes_product_add_new_attributepublic\inc\bytes-product-attributes.php:7
authwp_ajax_bytes_product_save_attributespublic\inc\bytes-product-attributes.php:9
noprivwp_ajax_bytes_product_save_attributespublic\inc\bytes-product-attributes.php:10
authwp_ajax_bytes_save_productpublic\inc\bytes-save-product.php:3
authwp_ajax_bytes_edit_productpublic\inc\bytes-save-product.php:6
WordPress Hooks 25
actioninitbytes-add-product-frontend-for-woocommerce.php:85
actionadmin_noticesbytes-add-product-frontend-for-woocommerce.php:112
filtercodecabin_deactivate_feedback_form_pluginsbytes-add-product-frontend-for-woocommerce.php:132
actionplugins_loadedincludes\class-bytes-add-product-frontend-for-woocommerce.php:67
actionadmin_enqueue_scriptsincludes\class-bytes-add-product-frontend-for-woocommerce.php:76
actionadmin_enqueue_scriptsincludes\class-bytes-add-product-frontend-for-woocommerce.php:77
actionadmin_menuincludes\class-bytes-add-product-frontend-for-woocommerce.php:79
actionadmin_initincludes\class-bytes-add-product-frontend-for-woocommerce.php:80
actionadmin_initincludes\class-bytes-add-product-frontend-for-woocommerce.php:81
actionadmin_initincludes\class-bytes-add-product-frontend-for-woocommerce.php:82
actionadmin_initincludes\class-bytes-add-product-frontend-for-woocommerce.php:83
filtermanage_product_posts_columnsincludes\class-bytes-add-product-frontend-for-woocommerce.php:84
actionmanage_product_posts_custom_columnincludes\class-bytes-add-product-frontend-for-woocommerce.php:85
actionwp_enqueue_scriptsincludes\class-bytes-add-product-frontend-for-woocommerce.php:93
actionwp_enqueue_scriptsincludes\class-bytes-add-product-frontend-for-woocommerce.php:94
filterpage_templateincludes\class-bytes-add-product-frontend-for-woocommerce.php:95
filterwoocommerce_account_menu_itemsincludes\class-bytes-add-product-frontend-for-woocommerce.php:96
actionwp_loadedincludes\class-bytes-add-product-frontend-for-woocommerce.php:97
actionwoocommerce_account_product-list_endpointincludes\class-bytes-add-product-frontend-for-woocommerce.php:98
actionwp_loadedincludes\class-bytes-add-product-frontend-for-woocommerce.php:99
actionwoocommerce_account_edit-product-form_endpointincludes\class-bytes-add-product-frontend-for-woocommerce.php:100
actionwp_loadedincludes\class-bytes-add-product-frontend-for-woocommerce.php:101
actionsave_postincludes\class-bytes-add-product-frontend-for-woocommerce.php:102
filterwpincludes\class-bytes-add-product-frontend-for-woocommerce.php:104
filterbody_classincludes\class-bytes-add-product-frontend-for-woocommerce.php:105
Maintenance & Trust

Add Product Frontend for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 1, 2025
PHP min version7.4
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs90
Developer Profile

Add Product Frontend for WooCommerce Developer Profile

Bytes Technolab

2 plugins · 130 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add Product Frontend for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Add Product Frontend for WooCommerce