CVE-2026-88929
Received Received - Intake

Unauthenticated Product Data Exposure in WooCommerce Badge Plugin

Vulnerability report for CVE-2026-88929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to unauthenticated users, allowing them to read the title, description and price of draft, pending and private products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Sale Booster' versions 7.0.0 to 7.5.1. It allows unauthenticated users to access non-public product details, including titles, descriptions, and prices, even for draft, pending, or private products. The issue arises because the plugin fails to verify whether a product is published before sharing its information.

Detection Guidance

To detect this vulnerability, check if your WordPress site is running the 'Sale Booster' plugin version 7.0.0 to 7.5.1. You can verify the version via the WordPress admin panel under Plugins or by inspecting the plugin files. Test if unauthenticated users can access draft, pending, or private product details by attempting to view such products directly via their URLs.

Impact Analysis

Unauthenticated users could view sensitive product information that should be restricted, such as draft, pending, or private product details. This could lead to data leaks, competitive disadvantages, or unauthorized access to confidential pricing and descriptions.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR by exposing personal or sensitive product data to unauthorized users. It may also conflict with HIPAA if product details include protected health information.

Mitigation Strategies

Immediately update the 'Sale Booster' plugin to version 7.5.2 or later. If updating is not possible, consider temporarily disabling the plugin until the update is applied. Ensure all product visibility settings are correctly configured to restrict access to non-published products.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart