CVE-2025-12115: WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration
The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This is due to the plugin not disabling the ability to name a custom price when it has been specifically disabled for a product. This makes it possible for unauthenticated attackers to purchase products at prices less than they should be able to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12115?
CVE-2025-12115 has a medium severity rating due to its potential to allow unauthorized price modifications.
How do I fix CVE-2025-12115?
To fix CVE-2025-12115, update the WPC Name Your Price for WooCommerce plugin to the latest version beyond 2.1.9.
What versions are affected by CVE-2025-12115?
CVE-2025-12115 affects all versions of WPC Name Your Price for WooCommerce up to and including 2.1.9.
What type of vulnerability is CVE-2025-12115?
CVE-2025-12115 is an unauthorized price alteration vulnerability.
Who is the vendor of CVE-2025-12115?
The vendor of CVE-2025-12115 is WPC, responsible for the Name Your Price for WooCommerce plugin.