CVE-2025-12115
WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration
highClient-Side Enforcement of Server-Side Security
7.5
CVSS Score
7.5
CVSS Score
high
Severity
2.2.0
Patched in
1d
Time to patch
Description
The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
High
Integrity
None
Availability
Technical Details
Affected versions
<=2.1.9PublishedOctober 30, 2025
Last updatedOctober 31, 2025
Affected pluginwpc-name-your-price
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.