CVE-2026-32406: WordPress WPC Product Bundles for WooCommerce plugin <= 8.4.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Product Bundles for WooCommerce: from n/a through <= 8.4.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32406?
CVE-2026-32406 is considered a high severity vulnerability due to unauthorized access risks.
How do I fix CVE-2026-32406?
To fix CVE-2026-32406, update the WPC Product Bundles for WooCommerce plugin to version 8.4.6 or later.
What kind of vulnerability is CVE-2026-32406?
CVE-2026-32406 is a Broken Access Control vulnerability that allows exploitation of incorrectly configured access control security levels.
Which versions of WPC Product Bundles for WooCommerce are affected by CVE-2026-32406?
CVE-2026-32406 affects versions of WPC Product Bundles for WooCommerce up to and including version 8.4.5.
Who is the vendor associated with CVE-2026-32406?
The vendor associated with CVE-2026-32406 is WPClever, the developer of the WPC Product Bundles for WooCommerce plugin.