MEDIUM (6.9)
    Plugin

    Cross-Site Request Forgery in WooBeWoo Product Pricing Table Plugin

    Published Date: 4/15/2026
    CVE ID: CVE-2026-1852

    Summary

    The WooBeWoo Product Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to insufficient nonce validation in certain functions. This allows attackers to conduct unauthorized actions such as injecting web scripts or deleting pricing tables by tricking administrators into interacting with malicious requests.

    Vulnerability Details

    CVE-2026-1852 identifies a vulnerability in the WooBeWoo Product Pricing Table plugin for WordPress. Specifically, all versions up to and including 1.1.0 are susceptible to CSRF attacks. The issue arises from inadequate checks on nonce tokens in the updateLabel() and remove() functions, which are essential for verifying the intention and legitimacy of user actions. Without appropriate nonce validation, malicious actors can craft requests to these functions and execute them by enticing an administrator to click on a manipulated link. If successful, such actions can result in arbitrary script injection or the unintended deletion of pricing tables. This vulnerability highlights the critical need for improved input validation and user interaction verification.

    Recommendations

    To mitigate this vulnerability, ensure that all actions requiring user permissions include proper nonce validation to authenticate requests. Consider implementing additional layers of user confirmation before executing sensitive actions and educating site administrators on recognizing and avoiding suspicious links or requests.

    Available Fixes

    Last Updated: 4/16/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More