CVE-2026-93508
Received Received - Intake

WC Fields Factory Plugin Authenticated Post Meta Manipulation

Vulnerability report for CVE-2026-93508, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wc_fields_factory wc_fields_factory to 4.1.11 (exc)
wpengine wc_fields_factory to 4.1.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the WC Fields Factory WordPress plugin before version 4.1.11 allows authenticated users with Subscriber-level access or higher to modify arbitrary post meta data on any post, including WooCommerce products. This includes creating, editing, or deleting post meta and changing pricing rules to reduce a product's checkout price due to improper access restrictions in the plugin's field-management AJAX action.

Detection Guidance

Check if the WC Fields Factory plugin is installed and verify its version. If it is below 4.1.11, the system is vulnerable. Look for unauthorized modifications to post meta data or pricing rules in WooCommerce products.

Impact Analysis

An attacker with Subscriber access or higher could manipulate product prices, delete or alter important post data, or disrupt WooCommerce functionality. This could lead to financial losses, data corruption, or unauthorized changes to product information on affected WordPress sites.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR if personal data in post meta is altered or deleted without authorization. For HIPAA, if the site handles protected health information, unauthorized changes to pricing or data could violate integrity and access control requirements.

Mitigation Strategies

Update the WC Fields Factory plugin to version 4.1.11 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied. Review post meta data and pricing rules for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart