CVE-2026-16620: WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfixed vector from CVE-2025-12115, whose 2.2.0 fix only addressed applying a custom price to products where Name Your Price is disabled and left the Select-mode allowlist unenforced through 2.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPC Name Your Price for WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 2.2.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16620?
The severity of CVE-2026-16620 is classified as high with a score of 7.5.
How does CVE-2026-16620 affect WooCommerce users?
CVE-2026-16620 allows unauthenticated visitors to manipulate product prices below merchant-defined values in the 'Select' price mode.
How do I fix CVE-2026-16620?
To fix CVE-2026-16620, update the WPC Name Your Price for WooCommerce plugin to version 2.2.5 or later.
Are there any known exploits for CVE-2026-16620?
Yes, CVE-2026-16620 presents a risk of price manipulation by unauthenticated users, which can lead to revenue loss for merchants.
What versions of WPC Name Your Price for WooCommerce are vulnerable to CVE-2026-16620?
WPC Name Your Price for WooCommerce versions prior to 2.2.5 are vulnerable to CVE-2026-16620.