CVE-2026-105878: WordPress YITH WooCommerce Product Bundles plugin <= 2.29.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YITH WooCommerce Product Bundles (yith-woocommerce-product-bundles)to a version that resolves this vulnerability.Fixed in 2.30.0
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates the issue can be exploited remotely with low attack complexity and requires no privileges or user interaction.
What is the expected impact if exploitation succeeds?
The reported impact is limited to integrity: an attacker may be able to make unauthorized modifications. No confidentiality or availability impact is indicated by the CVSS vector.
Which plugin versions are affected?
The affected range is reported as versions through 2.29.0. No lower version boundary is provided.