The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.17. This is due to missing or incorrect nonce validation on the 'maybe_duplicate' function. This makes it possible for unauthenticated attackers to duplicate and publish product field groups, including draft and pending field groups, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maartenbelmans
Maartenbelmans advanced Product Fields Product Addons For Woocommerce Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Maartenbelmans
Maartenbelmans advanced Product Fields Product Addons For Woocommerce Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
Tue, 09 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.17. This is due to missing or incorrect nonce validation on the 'maybe_duplicate' function. This makes it possible for unauthenticated attackers to duplicate and publish product field groups, including draft and pending field groups, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.17 - Cross-Site Request Forgery to Product Field Group Duplication and Publication | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-09T17:23:32.069Z
Updated: 2025-12-09T20:42:36.512Z
Reserved: 2025-12-02T20:51:17.716Z
Link: CVE-2025-13924
Updated: 2025-12-09T20:19:31.799Z
Status : Awaiting Analysis
Published: 2025-12-09T18:15:49.037
Modified: 2025-12-09T18:36:29.050
Link: CVE-2025-13924
No data.